A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-8602

CVE-2026-8602: ScadaBR Authentication Bypass Vulnerability

CVE-2026-8602 is an authentication bypass flaw in ScadaBR 1.2.0 that allows attackers to inject arbitrary sensor readings without authentication. This article covers the technical details, affected versions, and mitigation.

Published: May 21, 2026

CVE-2026-8602 Overview

CVE-2026-8602 is a Missing Authentication for Critical Function vulnerability [CWE-306] in ScadaBR version 1.2.0. The flaw allows an unauthenticated attacker to send crafted HTTP GET requests to the Supervisory Control and Data Acquisition (SCADA) system and inject arbitrary sensor readings. CISA published the issue in ICS Advisory ICSA-26-139-03. ScadaBR is an open-source SCADA platform used in industrial control system (ICS) deployments, where falsified telemetry can influence operator decisions and automated control logic.

Critical Impact

Unauthenticated network attackers can inject arbitrary sensor readings into ScadaBR, corrupting industrial telemetry and undermining the integrity of control decisions.

Affected Products

  • ScadaBR version 1.2.0
  • Deployments exposing the ScadaBR HTTP interface to untrusted networks
  • Industrial control environments relying on ScadaBR for sensor data acquisition

Discovery Timeline

  • 2026-05-19 - CVE-2026-8602 published to the National Vulnerability Database (NVD)
  • 2026-05-19 - CISA publishes ICS Advisory ICSA-26-139-03
  • 2026-05-19 - Last updated in NVD database

Technical Details for CVE-2026-8602

Vulnerability Analysis

The vulnerability stems from the absence of authentication on an HTTP endpoint that accepts sensor data writes. Because the endpoint performs no identity or session validation, any client that can reach the ScadaBR HTTP listener can submit values. The attack requires only a network path to the target and a simple HTTP GET request. There is no requirement for user interaction, credentials, or prior knowledge of the deployment.

The integrity impact is high: injected values flow into the SCADA historian and runtime data points. Downstream alarms, dashboards, automation scripts, and operator displays consume these values as ground truth. Availability of the control process can also degrade when fabricated readings trigger automated responses such as shutdowns or setpoint changes. Confidentiality is not directly affected by this flaw.

Root Cause

The root cause is Missing Authentication for Critical Function [CWE-306]. The sensor write functionality is exposed without enforcing authentication or authorization, violating the principle that state-changing operations on industrial data must require a verified identity. The use of HTTP GET for a write operation further compounds the issue, as GET requests are easily replayed, logged, and triggered from third-party contexts.

Attack Vector

An attacker reaches the ScadaBR HTTP service over the network and issues a GET request containing the target data point identifier and the desired value. ScadaBR accepts the request, writes the value to the corresponding sensor channel, and propagates it through the SCADA pipeline. No authentication header, session cookie, or token is validated. Refer to the CISA ICS Advisory ICSA-26-139-03 for endpoint-specific details.

Detection Methods for CVE-2026-8602

Indicators of Compromise

  • Unauthenticated HTTP GET requests to ScadaBR sensor or data point write endpoints originating from unexpected source addresses
  • Sudden, statistically improbable changes in sensor values that do not correlate with physical process state
  • Web server access logs showing high-frequency GET requests targeting data point identifiers
  • Alarm events triggered by values that fall outside historical operating ranges without corresponding process events

Detection Strategies

  • Monitor ScadaBR HTTP access logs for requests to sensor update paths that lack authenticated session context
  • Correlate sensor value changes with operator activity and SCADA write commands to identify out-of-band writes
  • Deploy network intrusion detection signatures for HTTP GET patterns targeting ScadaBR endpoints from non-engineering subnets

Monitoring Recommendations

  • Forward ScadaBR application and web server logs to a centralized log platform with retention sufficient for ICS incident review
  • Establish baselines for each data point and alert on deviations that exceed expected physical tolerances
  • Track all external connections to the ScadaBR host and alert on any source outside the authorized OT management network

How to Mitigate CVE-2026-8602

Immediate Actions Required

  • Remove direct network exposure of ScadaBR 1.2.0 from any untrusted or corporate network segment
  • Place ScadaBR behind a reverse proxy or VPN that enforces authentication before traffic reaches the application
  • Restrict inbound access to the ScadaBR HTTP port using host-based and network firewalls, allowing only known engineering workstations
  • Review historian data for anomalous values written during periods when the system may have been reachable from unauthorized sources

Patch Information

No vendor patch is referenced in the NVD entry or the CISA advisory at the time of publication. Operators should consult the CISA ICS Advisory ICSA-26-139-03 for the latest vendor guidance and apply any future fixed release for ScadaBR as soon as it becomes available.

Workarounds

  • Segment ScadaBR into an isolated OT network following ISA/IEC 62443 zone and conduit guidance
  • Require VPN access with multi-factor authentication for any remote interaction with the SCADA host
  • Disable or block the affected HTTP endpoints at a reverse proxy if they are not required for operations
  • Implement strict allowlists at the perimeter to permit only authorized engineering source addresses
bash
# Example: restrict inbound access to ScadaBR HTTP port using iptables
iptables -A INPUT -p tcp --dport 8080 -s 10.10.20.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 8080 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechScadabr

  • SeverityHIGH

  • CVSS Score8.8

  • EPSS Probability0.08%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-306
  • Technical References
  • CISA ICS Advisory ICSA-26-139-03
  • Related CVEs
  • CVE-2026-8605: ScadaBR Auth Bypass Vulnerability

  • CVE-2025-70973: ScadaBR Session Fixation Vulnerability

  • CVE-2026-8603: ScadaBR OS Command Injection Vulnerability

  • CVE-2026-8604: ScadaBR CSRF Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English