🔐 CVE Alert

CVE-2026-34185

UNKNOWN 0.0

SQL Injection in AlanWeb SCADA

CVSS Score
0.0
EPSS Score
0.3%
EPSS Percentile
21th

AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database. This issue was fixed in AlanWeb SCADA version 9.8.5

CWE CWE-89
Vendor control system
Product alanweb scada
Published Apr 9, 2026
Last Updated Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for control system alanweb scada

Be the first to know when new unknown vulnerabilities affecting control system alanweb scada are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Control System / AlanWeb SCADA
0 < 9.8.5

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/posts/2026/04/CVE-2026-4901/ control-system.pl: https://control-system.pl/

Credits

Jarosław "Jahrek" Kamiński - Securitum