CVE-2026-34184 (matched: php)

  • Friday, 14th August, 2026
  • 10:06am

A security flaw has been found in AlanWeb SCADA software that does not restrict access to certain system directories. This means unauthorized people can view and interact with files in these folders without needing permission.

If you use this software for your website or connected systems, attackers could exploit this flaw to read all files in the unprotected directories, run select files within them, and even execute PHP scripts directly on any database linked to your AlanWeb SCADA instance. This could lead to data theft, unauthorized changes to your site or database, or other harmful activity.

The issue was resolved in AlanWeb SCADA version 9.8.5. Updating to this version or a newer release will close the security gap for users of the software.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-34184

« Back