CVE-2026-34184 (matched: php)

  • Sunday, 16th August, 2026
  • 10:08am

A security flaw has been identified in AlanWeb SCADA software. The flaw means the software does not check if people are authorized to access certain system folders, so it does not verify that visitors have permission to view or interact with files stored in those locations. This gap allows unauthorized attackers to read all files in these unprotected folders, and even run some of the files kept there. The most serious risk is that an attacker could run PHP scripts directly on the system's connected database, which could lead to stolen data, website outages, or unauthorized access to connected systems. This issue has been fixed in AlanWeb SCADA version 9.8.5.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-34184

« Back