CVE-2021-26828
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
- Published
- Jun 11, 2021
- Updated
- Dec 4, 2025
- Assigning CNA
- mitre
- Evidence observed
- Dec 3, 2025
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 98.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
Sources
2- CVE-2021-26828_ScadaBR_RCEExploit
Proof-of-concept exploit for CVE-2021-26828 enabling authenticated remote code execution on ScadaBR SCADA systems via JSP file upload. Supports Windows and Linux targets with reverse shell payloads.
- CVE-2021-26828-UltimateExploit
ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.