Skip to content
COOEY

FAIL › dossier

ScadaBR

PRODUCT

· dossier confidence 60%

ScadaBR is a Brazilian open-source SCADA platform with a critically compromised security posture. The vendor has failed to address severe vulnerabilities, including remote code execution and OS command injection, leaving industrial control systems exposed to exploitation.

PROFILE
CategorySCADA SoftwareWhat they doScadaBR is a free, open-source supervisory control and data acquisition (SCADA) application used for process control and automation systems, developed by MCA Sistemas.Founded2009HQBrazil Websitehttps://www.scadabr.com.br/ ↗
SECURITY POSTURE

The security posture is critically weak, characterized by a severe backlog of unpatched high and critical vulnerabilities spanning multiple years, including remote code execution, OS command injection, missing authentication, and hard-coded credentials.

Notable failures
  • CVE-2021-26828: Unpatched RCE via JSP execution
  • CVE-2021-26829: Unpatched XSS exploited in the wild
  • CVE-2026-8603: Critical OS Command Injection in v1.2.0
  • CVE-2026-8602: Critical Missing Authentication for Critical Function in v1.2.0
  • CVE-2026-8605: Critical Hard-Coded Credentials in v1.2.0
Patterns: Repeated unpatched critical vulnerabilities in major releases; Failure to patch high-severity RCE and XSS flaws; Insecure coding practices including hard-coded credentials and missing authentication
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2025-12-03 CVE-2021-26828 high OpenPLC ScadaBR exposed arbitrary JSP execution
2025-11-28 CVE-2021-26829 high OpenPLC ScadaBR had an unpatched XSS vulnerability exploited in the wild
2026-05-19 CVE-2026-8603 critical CVE-2026-8603: In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an a
2026-05-19 CVE-2026-8603 critical CVE-2026-8603: In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an a
2026-05-19 CVE-2026-8602 critical CVE-2026-8602: In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnera
2026-05-19 CVE-2026-8602 critical CVE-2026-8602: In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnera
2026-05-19 CVE-2026-8605 critical CVE-2026-8605: In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could al
2026-05-19 CVE-2026-8605 critical CVE-2026-8605: In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could al
DOSSIER SOURCES
Open questions: Who maintains the ScadaBR project? · What is the current version of ScadaBR and its patching cadence?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-11 03:53:22.033797+00:00