High severity8.8NVD Advisory· Published Apr 9, 2026· Updated Apr 20, 2026
CVE-2026-34185
CVE-2026-34185
Description
Hydrosystem Control System is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.This issue was fixed in Hydrosystem Control System version 9.8.5
Affected products
1- cpe:2.3:a:hydrosystem.poznan:control_system:*:*:*:*:*:*:*:*Range: <9.8.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cert.pl/posts/2026/04/CVE-2026-4901/nvdVendor Advisory
- www.hydrosystem.poznan.plnvdProduct
News mentions
0No linked articles in our index yet.