{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2021-26829",
  "revision": 1,
  "title": "OpenPLC ScadaBR — stored script injection in system settings",
  "summary": "OpenPLC ScadaBR through 0.9.1 on Linux and 1.12.4 on Windows stores script from the system settings page and runs it in the next operator's session. Hacktivist crews have used it against operational sites.",
  "source_type": "cve",
  "severity": "medium",
  "cvss": {
    "score": 5.4,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
    "version": "3.1"
  },
  "epss": 0.4805,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2025-11-28",
    "prerequisites": "The ability to store content on the settings page, and an operator who later opens it."
  },
  "mitre_attack": [
    "T1059.007"
  ],
  "kill_chain": "execution",
  "recommended_action": "Move to a maintained supervisory control build now; keep the interface off routable networks and review settings pages for content nobody entered.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2021-26829",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2021-26829",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2021-26829",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26829",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3615/4"
    },
    {
      "type": "exploit",
      "url": "https://youtu.be/Xh6LPCiLMa8"
    },
    {
      "type": "writeup",
      "url": "https://www.forescout.com/blog/anatomy-of-a-hacktivist-attack-russian-aligned-group-targets-otics/"
    }
  ],
  "published_at": "2021-06-11T12:15:12.053Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "openplc",
    "scadabr",
    "ics",
    "ot",
    "cross-site-scripting",
    "kev"
  ]
}
