A security vulnerability has been identified in AlanWeb SCADA, a software platform some website and operational system operators may use. The flaw means the software does not properly enforce access restrictions for certain system directories.
This gap allows unauthorized attackers to read all files stored in these unprotected directories, and even run some of the files located there. Most critically, attackers could execute PHP scripts directly on the system’s connected database, which could lead to data theft, service disruption, or unauthorized changes to your systems and data.
The issue has been fixed in AlanWeb SCADA version 9.8.5.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-34184