TL;DR
A critical SQL injection flaw hits Weidmueller PROCON-WEB SCADA. Tracked as CVE-2026-16462, it scores a CVSS of 9.8. A remote, unauthenticated attacker can run arbitrary SQL commands on affected systems.
- CVE: CVE-2026-16462
- CVSS: 9.8 (Critical · CVSSv3)
- Product: Weidmueller Interface PROCON-WEB SCADA
- Affected: 1.0.0
- Impact: SQL injection via unauthenticated GetGridData endpoint
- Status: No confirmed exploitation yet
- EPSS: 0.4% (30-day)
- Action: See vendor advisory
Why it matters
SCADA software runs industrial and building automation. Therefore a break-in can disrupt physical processes. This flaw needs no login, so the barrier to attack is low. An attacker could read, change, or delete data. From there, they could push further into the underlying system.
How the attack works
The bug sits in the “GetGridData” endpoint. According to CERT@VDE, that endpoint “is not properly sanitized.” As a result, crafted input reaches the database as SQL. The advisory warns this lets “a remote unauthenticated attacker to execute arbitrary SQL commands.” For safety, this report omits any exploit details.
Affected versions
The flaw affects PROCON-WEB SCADA versions 6.11.2 and earlier, back to 1.0.0. It spans a long list of Weidmueller model numbers. No public exploitation or proof-of-concept has been confirmed so far.
Patch and mitigation
Update PROCON-WEB SCADA to version 6.11.3 now. No workaround is listed, so the patch is the fix. Spain’s INCIBE-CERT also flags the bug, rating it 9.3 under CVSS 4.0. Read the full CERT@VDE advisory for the affected model list.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.