CVE-2026-34184 (matched: php)

  • Friday, 14th August, 2026
  • 22:04pm

A security flaw has been found in AlanWeb SCADA software. The software fails to require proper authorization to access certain folders on systems where it is installed. This means unauthorized users could read every file stored in those folders, and even run some of the files, including PHP scripts linked to the system's connected database.

This issue was fixed in AlanWeb SCADA version 9.8.5. If you use this software for your website or hosted tools, updating to version 9.8.5 or any newer release will address this vulnerability.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-34184

« Back