CVE-2026-34184 (matched: php)

  • Thursday, 13th August, 2026
  • 22:04pm

A security flaw has been identified in AlanWeb SCADA, a software platform some website owners use for managing industrial control systems and related data. The flaw means the software does not properly enforce access restrictions for certain folders on systems running it, leaving those folders unprotected. An attacker without authorized access to your system could browse every file stored in these unprotected folders, and even run some of the files they find there. Most critically, they could run PHP scripts directly on the database connected to your SCADA setup, which could lead to data theft, system disruption, or loss of control over your connected equipment. The developers of AlanWeb SCADA have already fixed this issue in version 9.8.5 of the software.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-34184

« Back