VYPR
High severity8.8NVD Advisory· Published Apr 9, 2026· Updated Aug 13, 2026

CVE-2026-34185

CVE-2026-34185

Description

AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.

This issue was fixed in AlanWeb SCADA version 9.8.5

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.