A security flaw has been identified in AlanWeb SCADA, a tool some website operators use to manage site functions. The flaw means the system does not enforce proper access restrictions for certain folders, so unauthorized people can view every file stored in those unprotected folders, and even run some of the files stored there. The most serious risk from this issue is that attackers could run PHP scripts directly on the system's connected database. This could lead to stolen customer or site data, broken website functionality, or unauthorized changes to your site and stored information. This flaw has been fixed in AlanWeb SCADA version 9.8.5.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-34184