CVE-2026-4901

AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user. This issue was fixed in AlanWeb SCADA version 9.8.5
Configurations

Configuration 1 (hide)

cpe:2.3:a:hydrosystem.poznan:control_system:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-09 10:16

Updated : 2026-08-13 10:17


NVD link : CVE-2026-4901

Mitre link : CVE-2026-4901

CVE.ORG link : CVE-2026-4901


JSON object : View

Products Affected

hydrosystem.poznan

  • control_system
CWE
CWE-532

Insertion of Sensitive Information into Log File