---
id: CVE-2026-34184
title: AlanWeb SCADA does not enforce authorization for some directories
summary: >-
  AlanWeb SCADA does not enforce authorization for some directories. This allows
  an unauthorized attacker to read all files in these directories and even
  execute some of them. Critically the attacker could run PHP scripts directly
  on the c…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-862
vendor: hydrosystem.poznan
product: control_system
affected:
  - control_system < 9.8.5
patched:
  - control_system 9.8.5
published: '2026-04-09'
updated: '2026-08-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34184'
references:
  - url: 'https://cert.pl/posts/2026/04/CVE-2026-4901/'
    label: cvd@cert.pl
  - url: 'https://control-system.pl/'
    label: cvd@cert.pl
tags:
  - nvd
epss: 0.00457
epssPercentile: 0.3702
ingestedAt: '2026-08-13T13:03:05.861Z'
---

## Overview

AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database.

This issue was fixed in AlanWeb SCADA version 9.8.5

## Affected

- `control_system < 9.8.5`

## Remediation

Upgrade past the affected range:

- `control_system 9.8.5`
