🔐 CVE Alert

CVE-2026-34184

UNKNOWN 0.0

Missing Authorization in Hydrosystem Control System

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Hydrosystem Control System does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database.This issue was fixed in Hydrosystem Control System version 9.8.5

CWE CWE-862
Vendor hydrosystem
Product control system
Published Apr 9, 2026
Last Updated Apr 9, 2026
Stay Ahead of the Next One

Get instant alerts for hydrosystem control system

Be the first to know when new unknown vulnerabilities affecting hydrosystem control system are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Hydrosystem / Control System
0 < 9.8.5

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/posts/2026/04/CVE-2026-4901/ hydrosystem.poznan.pl: https://www.hydrosystem.poznan.pl/

Credits

Jarosław "Jahrek" Kamiński - Securitum