FAIL › dossier
ScadaBR
PRODUCT· dossier confidence 60%
ScadaBR is a Brazilian open-source SCADA platform with a critically compromised security posture. The vendor has failed to address severe vulnerabilities, including remote code execution and OS command injection, leaving industrial control systems exposed to exploitation.
PROFILE
CategorySCADA SoftwareWhat they doScadaBR is a free, open-source supervisory control and data acquisition (SCADA) application used for process control and automation systems, developed by MCA Sistemas.Founded2009HQBrazil
Websitehttps://www.scadabr.com.br/ ↗
SECURITY POSTURE
The security posture is critically weak, characterized by a severe backlog of unpatched high and critical vulnerabilities spanning multiple years, including remote code execution, OS command injection, missing authentication, and hard-coded credentials.
Notable failures
- CVE-2021-26828: Unpatched RCE via JSP execution
- CVE-2021-26829: Unpatched XSS exploited in the wild
- CVE-2026-8603: Critical OS Command Injection in v1.2.0
- CVE-2026-8602: Critical Missing Authentication for Critical Function in v1.2.0
- CVE-2026-8605: Critical Hard-Coded Credentials in v1.2.0
Patterns: Repeated unpatched critical vulnerabilities in major releases; Failure to patch high-severity RCE and XSS flaws; Insecure coding practices including hard-coded credentials and missing authentication
FAILURE HISTORY · 8
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-12-03 | CVE-2021-26828 | high | OpenPLC ScadaBR exposed arbitrary JSP execution |
| 2025-11-28 | CVE-2021-26829 | high | OpenPLC ScadaBR had an unpatched XSS vulnerability exploited in the wild |
| 2026-05-19 | CVE-2026-8603 | critical | CVE-2026-8603: In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an a |
| 2026-05-19 | CVE-2026-8603 | critical | CVE-2026-8603: In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an a |
| 2026-05-19 | CVE-2026-8602 | critical | CVE-2026-8602: In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnera |
| 2026-05-19 | CVE-2026-8602 | critical | CVE-2026-8602: In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnera |
| 2026-05-19 | CVE-2026-8605 | critical | CVE-2026-8605: In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could al |
| 2026-05-19 | CVE-2026-8605 | critical | CVE-2026-8605: In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could al |
DOSSIER SOURCES
- ScadaBR - LIMSWiki · www.limswiki.org
- ScadaBR (ScadaBR) · GitHub · github.com
- ScadaBR · www.scadabr.com.br
Open questions: Who maintains the ScadaBR project? · What is the current version of ScadaBR and its patching cadence?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-11 03:53:22.033797+00:00