---
id: CVE-2026-34185
title: >-
  AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input
  parameters
summary: >-
  AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input
  parameters. Because no protections are in place, an authenticated attacker can
  inject arbitrary SQL commands, potentially gaining full control over the
  database.

  …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: hydrosystem.poznan
product: control_system
affected:
  - control_system < 9.8.5
patched:
  - control_system 9.8.5
published: '2026-04-09'
updated: '2026-08-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34185'
references:
  - url: 'https://cert.pl/posts/2026/04/CVE-2026-4901/'
    label: cvd@cert.pl
  - url: 'https://control-system.pl/'
    label: cvd@cert.pl
tags:
  - nvd
epss: 0.00466
epssPercentile: 0.37587
ingestedAt: '2026-08-13T13:03:05.952Z'
---

## Overview

AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.

This issue was fixed in AlanWeb SCADA version 9.8.5

## Affected

- `control_system < 9.8.5`

## Remediation

Upgrade past the affected range:

- `control_system 9.8.5`
