top of page
perceptive_background_267k.jpg

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

Published:

28 July 2026 at 00:00:00

Alert date:

28 July 2026 at 13:00:57

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Web Technologies, Database & Storage, Zero-Day Vulnerabilities

A critical SQL injection vulnerability has been identified in PROCON-WEB SCADA affecting the 'GetGridData' endpoint. The endpoint lacks proper input sanitization, enabling remote unauthenticated attackers to execute arbitrary SQL commands. No authentication is required to exploit this vulnerability, making it particularly dangerous. The flaw affects industrial control system (ICS) SCADA software, which is commonly used in critical infrastructure environments. Successful exploitation could lead to unauthorized data access, data manipulation, or further compromise of the underlying system. The vulnerability has been assigned CVE-2026-16462 and is documented by both NVD and CERT VDE.

Technical details

Mitigation steps:

Affected products:

PROCON-WEB SCADA

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page