CVE-2026-94148 Overview
CVE-2026-94148 is an information disclosure vulnerability in ScadaBR versions up to 1.1. The flaw resides in the EmportDwr.createExportJSON function accessible through the /ScadaBR/export_project.htm endpoint. The Export Project endpoint lacks the Permissions.ensureAdmin() gate that already protects the corresponding import path. Unauthenticated remote attackers can invoke the export function and retrieve project configuration data. The issue is tracked under CWE-200: Exposure of Sensitive Information to an Unauthorized Actor. A public exploit disclosure exists, and upgrading to version 1.2.0 (commit c852b4988a15bce6011ef169299ad604538f70a9) resolves the missing authorization check.
Critical Impact
Remote unauthenticated attackers can export ScadaBR project data, exposing SCADA configuration details that support reconnaissance of industrial control systems.
Affected Products
- ScadaBR versions up to and including 1.1
- ScadaBR Export Project component (/ScadaBR/export_project.htm)
- EmportDwr.createExportJSON function
Discovery Timeline
- 2026-09-21 - CVE-2026-94148 published to the National Vulnerability Database (NVD)
- 2026-09-21 - Last updated in the NVD database
Technical Details for CVE-2026-94148
Vulnerability Analysis
ScadaBR is an open source Supervisory Control and Data Acquisition (SCADA) platform used to monitor and control industrial processes. The vulnerability originates in the Export Project endpoint, which serves serialized project data via Direct Web Remoting (DWR). While the import counterpart correctly invokes Permissions.ensureAdmin() to restrict access to administrative users, the export path was left without an equivalent authorization check.
An unauthenticated remote requester can call EmportDwr.createExportJSON through /ScadaBR/export_project.htm and receive a JSON export of the current project. That export contains data source definitions, point configurations, users, and other operational metadata useful for mapping the underlying industrial environment.
Root Cause
The root cause is a missing authorization check on a server-side endpoint that exposes sensitive resources. The application relied on a control that was inconsistently applied across paired functions. Only the import path enforced Permissions.ensureAdmin(); the export path exposed the same underlying data without any privilege verification, classifying the flaw under CWE-200.
Attack Vector
Exploitation is network-based and requires no authentication or user interaction. An attacker sends an HTTP request to the exposed /ScadaBR/export_project.htm endpoint and parses the returned JSON. Because ScadaBR deployments are frequently reachable from operational networks, exposure of project data enables reconnaissance for follow-on attacks against industrial devices.
// Patch: WebContent/WEB-INF/web.xml — disable DWR debug servlet
<servlet-class>org.directwebremoting.servlet.DwrServlet</servlet-class>
<init-param>
<param-name>debug</param-name>
- <param-value>true</param-value>
+ <param-value>false</param-value>
</init-param>
<init-param>
<param-name>publishContainerAs</param-name>
Source: ScadaBR commit c852b49
// Patch: WebContent/WEB-INF/jsp/login.jsp — escape reflected username value
<spring:bind path="login.username">
<label for="username"><fmt:message key="login.userId"/></label>
- <input id="username" type="text" name="username" value="${status.value}" maxlength="40" autofocus>
+ <input id="username" type="text" name="username" value="${fn:escapeXml(status.value)}" maxlength="40" autofocus>
<c:if test="${status.error}">
<span class="errorMessage">${status.errorMessage}</span>
</c:if>
Source: ScadaBR commit c852b49. These patch fragments accompany the broader hardening commit that also gates the export function with Permissions.ensureAdmin().
Detection Methods for CVE-2026-94148
Indicators of Compromise
- Unauthenticated HTTP GET or POST requests to /ScadaBR/export_project.htm from external or unexpected internal sources.
- DWR calls invoking EmportDwr.createExportJSON outside authenticated administrator sessions.
- Large outbound JSON responses originating from the ScadaBR web application to non-administrator clients.
Detection Strategies
- Inspect web server and reverse proxy logs for requests to export_project.htm that lack a valid administrator session cookie.
- Alert on repeated requests to the Export Project endpoint from a single source IP within a short time window, indicating scripted enumeration.
- Correlate DWR endpoint access patterns with authentication logs to identify calls that bypass the login flow.
Monitoring Recommendations
- Enable verbose access logging on the servlet container hosting ScadaBR and forward logs to a central analytics platform.
- Monitor egress traffic from ScadaBR hosts for anomalous JSON payload sizes that could represent exported project data.
- Track version banners and file hashes of deployed ScadaBR instances to confirm patched builds are running.
How to Mitigate CVE-2026-94148
Immediate Actions Required
- Upgrade ScadaBR to version 1.2.0 or later, which includes commit c852b4988a15bce6011ef169299ad604538f70a9.
- Restrict network access to the ScadaBR web interface using firewall rules or a reverse proxy that enforces authentication.
- Rotate credentials and review project configurations if unauthorized access to export_project.htm is suspected.
Patch Information
The fix is delivered in ScadaBR release v1.2. The relevant change adds the Permissions.ensureAdmin() check to the export path so that both import and export flows require administrator privileges. Additional hardening in the same commit escapes reflected form values in login.jsp and disables DWR debug mode in web.xml. Full commit context is available in the GitHub commit details.
Workarounds
- Place ScadaBR behind a reverse proxy that blocks unauthenticated requests to /ScadaBR/export_project.htm.
- Segment ScadaBR hosts onto an isolated management VLAN reachable only through a bastion or VPN.
- Disable or remove the Export Project endpoint via servlet mapping when the feature is not required in production.
# Example nginx rule to block unauthenticated access to the export endpoint
location = /ScadaBR/export_project.htm {
# Require authenticated session cookie or deny outright
if ($cookie_JSESSIONID = "") {
return 403;
}
allow 10.0.0.0/8;
deny all;
proxy_pass http://scadabr_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
