High severity8.8NVD Advisory· Published Apr 9, 2026· Updated Aug 13, 2026
CVE-2026-34185
CVE-2026-34185
Description
AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.
This issue was fixed in AlanWeb SCADA version 9.8.5
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:hydrosystem.poznan:control_system:*:*:*:*:*:*:*:*Range: <9.8.5
- Range: >=9.8.5
Patches
Vulnerability mechanics
References
2- cert.pl/posts/2026/04/CVE-2026-4901/nvdVendor Advisory
- control-system.plnvd
News mentions
0No linked articles in our index yet.