A security vulnerability has been identified in AlanWeb SCADA software. The flaw stems from the software not properly enforcing access authorization for certain system directories, leaving those folders unprotected.
This gap allows unauthorized attackers to view every file stored in these unsecured directories, and even run some of the files located there. Most critically, an unapproved user could directly execute PHP scripts connected to the software's linked database, which could let them access, change, or steal data stored in that database.
The issue has been resolved in AlanWeb SCADA version 9.8.5.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-34184