CVE-2026-34184 (matched: php)

  • Saturday, 15th August, 2026
  • 10:05am

A security flaw has been identified in AlanWeb SCADA, a software platform some users run for their operational systems. The issue occurs because the software does not verify whether users are authorized to access certain system folders.

This gap allows unauthorized attackers to view all files stored in these unprotected folders, run select files from the folders, and even execute PHP scripts directly on the database connected to the SCADA system. This could expose sensitive operational data, allow unauthorized changes to your systems, or cause disruptions to your services.

The vulnerability has been fixed in AlanWeb SCADA version 9.8.5. If you use this software for your operations, updating to this version will resolve the issue.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-34184

« Back