


Perceptive Security
SOC/SIEM Consultancy

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
Published:
28 July 2026 at 00:00:00
Alert date:
28 July 2026 at 13:00:57
Source:
nvd.nist.gov
Critical Infrastructure, Web Technologies, Database & Storage, Zero-Day Vulnerabilities
A critical SQL injection vulnerability has been identified in PROCON-WEB SCADA affecting the 'GetGridData' endpoint. The endpoint lacks proper input sanitization, enabling remote unauthenticated attackers to execute arbitrary SQL commands. No authentication is required to exploit this vulnerability, making it particularly dangerous. The flaw affects industrial control system (ICS) SCADA software, which is commonly used in critical infrastructure environments. Successful exploitation could lead to unauthorized data access, data manipulation, or further compromise of the underlying system. The vulnerability has been assigned CVE-2026-16462 and is documented by both NVD and CERT VDE.
Technical details
Mitigation steps:
Affected products:
PROCON-WEB SCADA
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
