{"id":"CVE-2026-4901","title":"AlanWeb SCADA saves sensitive information into a log file","summary":"AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive inf…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-532"],"vendor":"hydrosystem.poznan","product":"control_system","affected":["control_system < 9.8.5"],"patched":["control_system 9.8.5"],"published":"2026-04-09","updated":"2026-08-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-4901","references":[{"url":"https://cert.pl/posts/2026/04/CVE-2026-4901/","label":"cvd@cert.pl"},{"url":"https://control-system.pl/","label":"cvd@cert.pl"}],"tags":["nvd"],"epss":0.00259,"epssPercentile":0.1785,"ingestedAt":"2026-08-13T13:03:05.990Z","slug":"CVE-2026-4901","body":"## Overview\n\nAlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user.\n\nThis issue was fixed in AlanWeb SCADA version 9.8.5\n\n## Affected\n\n- `control_system < 9.8.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `control_system 9.8.5`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}