← All CVEs

CVE-2026-9645

critical · 9.9

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.

9.9
CVSS
0.4%
EPSS (exploit prob.)
35th
EPSS percentile
2026-05-28
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
scadabrscadabr1.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-9645