Umbra Wiki cve cve/CVE-2021-26828
Back to wiki

CVE-2021-26828 — OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability

provenance: imported · CVE: CVE-2021-26828

CVE-2021-26828: OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project OpenPLC
Product ScadaBR
Date added 2025-12-03
Due date 2025-12-24
Ransomware campaign use Unknown

Description

OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

Required action (CISA)

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes

This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/SCADA-LTS/Scada-LTS/pull/2174 ; https://nvd.nist.gov/vuln/detail/CVE-2021-26828

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-26828
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog