Vulnerability Description
AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user. This issue was fixed in AlanWeb SCADA version 9.8.5
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hydrosystem.Poznan | Control System | < 9.8.5 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-4901?
CVE-2026-4901 is a vulnerability with a CVSS score of 6.5 (MEDIUM). AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerabilit...
How severe is CVE-2026-4901?
CVE-2026-4901 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-4901?
Check the references section above for vendor advisories and patch information. Affected products include: Hydrosystem.Poznan Control System.