---
id: CVE-2026-4901
title: AlanWeb SCADA saves sensitive information into a log file
summary: >-
  AlanWeb SCADA saves sensitive information into a log file. Critically, user
  credentials are logged allowing the attacker to obtain further authorized
  access into the system. Combined with vulnerability CVE-2026-34184, these
  sensitive inf…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-532
vendor: hydrosystem.poznan
product: control_system
affected:
  - control_system < 9.8.5
patched:
  - control_system 9.8.5
published: '2026-04-09'
updated: '2026-08-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4901'
references:
  - url: 'https://cert.pl/posts/2026/04/CVE-2026-4901/'
    label: cvd@cert.pl
  - url: 'https://control-system.pl/'
    label: cvd@cert.pl
tags:
  - nvd
epss: 0.00259
epssPercentile: 0.1788
ingestedAt: '2026-08-13T13:03:05.990Z'
---

## Overview

AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user.

This issue was fixed in AlanWeb SCADA version 9.8.5

## Affected

- `control_system < 9.8.5`

## Remediation

Upgrade past the affected range:

- `control_system 9.8.5`
