{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/scadalts/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:scadalts:scadalts:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2026-84859"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ScadaLTS (2.8.1-rc)"],"_cs_severities":["low"],"_cs_tags":["sqli","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["ScadaLTS"],"content_html":"\u003cp\u003eScadaLTS version 2.8.1-rc is susceptible to an authenticated blind SQL injection vulnerability, identified as CVE-2026-84859. The flaw exists within the /api/events/search endpoint, which processes a JSON body containing a sortBy array. Because these array values are concatenated directly into a SQL ORDER BY clause without adequate sanitization or parameterization, an attacker can manipulate database queries. Any user with low-level privileges, including the ROLE_USER role, can leverage time-based or boolean-based SQL injection techniques to extract arbitrary information from the backend database. This impact includes the potential theft of user password hashes, which facilitates further unauthorized access or account takeover. Defenders must monitor API traffic for anomalous patterns originating from authenticated accounts and prioritize patching or isolating instances running the 2.8.1-rc build.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an authenticated attacker unauthorized read access to the ScadaLTS database. This enables the exfiltration of sensitive information, specifically user credential hashes, which could lead to wider system compromise across the Industrial Control System (ICS) environments where ScadaLTS is deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous JSON payloads targeting the /api/events/search endpoint.\u003c/li\u003e\n\u003cli\u003eAudit user roles and limit access to API endpoints to only necessary personnel to reduce the surface area for this authenticated exploit.\u003c/li\u003e\n\u003cli\u003eReview all database query patterns for evidence of SQL injection, specifically looking for unusual characters or SQL syntax (e.g., SLEEP, UNION, CASE) within the sortBy array parameters.\u003c/li\u003e\n\u003cli\u003ePatch or upgrade ScadaLTS to a version beyond 2.8.1-rc once a vendor-provided secure version is released.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T17:57:05Z","date_published":"2026-09-16T17:57:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-scadalts-sqli/","summary":"ScadaLTS 2.8.1-rc is vulnerable to an authenticated blind SQL injection via the sortBy parameter in the /api/events/search endpoint, allowing low-privileged users to exfiltrate database contents.","title":"Authenticated Blind SQL Injection in ScadaLTS","url":"https://feed.craftedsignal.io/briefs/2026-09-scadalts-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - ScadaLTS","version":"https://jsonfeed.org/version/1.1"}