CVE-2026-34185High· 8.8▾ TwilightAlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database. …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.
This issue was fixed in AlanWeb SCADA version 9.8.5
control_system < 9.8.5Upgrade past the affected range:
control_system 9.8.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-4901Medium· 6.5AlanWeb SCADA saves sensitive information into a log file
CVE-2026-34184Critical· 9.1AlanWeb SCADA does not enforce authorization for some directories
CVE-2025-13811Medium· 6.3A vulnerability was determined in jsnjfz WebStack-Guns 1.0
CVE-2025-13788High· 7.3A vulnerability has been found in Chanjet CRM up to 20251106
CVE-2023-7299Medium· 6.3A vulnerability was found in DataGear up to 4.60
CVE-2025-10592Medium· 6.3A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0