{"id":"CVE-2026-34185","title":"AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters","summary":"AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.\n…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-89"],"vendor":"hydrosystem.poznan","product":"control_system","affected":["control_system < 9.8.5"],"patched":["control_system 9.8.5"],"published":"2026-04-09","updated":"2026-08-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-34185","references":[{"url":"https://cert.pl/posts/2026/04/CVE-2026-4901/","label":"cvd@cert.pl"},{"url":"https://control-system.pl/","label":"cvd@cert.pl"}],"tags":["nvd"],"epss":0.0029,"epssPercentile":0.21829,"ingestedAt":"2026-08-13T13:03:05.952Z","slug":"CVE-2026-34185","body":"## Overview\n\nAlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.\n\nThis issue was fixed in AlanWeb SCADA version 9.8.5\n\n## Affected\n\n- `control_system < 9.8.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `control_system 9.8.5`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}