CVE-2026-34184: CWE-862: Missing Authorization in Control System AlanWeb SCADA
AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database. This issue was fixed in AlanWeb SCADA version 9.8.5
AI Analysis
Technical Summary
CVE-2026-34184 is a missing authorization vulnerability (CWE-862) in AlanWeb SCADA. The product does not enforce authorization controls on some directories, enabling unauthorized attackers to read all files within those directories and execute certain files, including PHP scripts that interact directly with the connected database. This could lead to unauthorized code execution and data exposure. The vulnerability has a CVSS 4.0 score of 8.8, indicating high severity. The issue was addressed and fixed in AlanWeb SCADA version 9.8.5.
Potential Impact
An attacker without any privileges can read sensitive files and execute PHP scripts on the connected database, potentially leading to unauthorized data access and remote code execution. This poses a significant risk to the confidentiality and integrity of the SCADA system and its data.
Mitigation Recommendations
Upgrade AlanWeb SCADA to version 9.8.5 or later, where this missing authorization vulnerability has been fixed. No other mitigation guidance is provided; patching is the recommended action.
CVE-2026-34184: CWE-862: Missing Authorization in Control System AlanWeb SCADA
Description
AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database. This issue was fixed in AlanWeb SCADA version 9.8.5
CVSS v4.0
Score 8.8high
Affected software
Control System
AlanWeb SCADA
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-34184 is a missing authorization vulnerability (CWE-862) in AlanWeb SCADA. The product does not enforce authorization controls on some directories, enabling unauthorized attackers to read all files within those directories and execute certain files, including PHP scripts that interact directly with the connected database. This could lead to unauthorized code execution and data exposure. The vulnerability has a CVSS 4.0 score of 8.8, indicating high severity. The issue was addressed and fixed in AlanWeb SCADA version 9.8.5.
Potential Impact
An attacker without any privileges can read sensitive files and execute PHP scripts on the connected database, potentially leading to unauthorized data access and remote code execution. This poses a significant risk to the confidentiality and integrity of the SCADA system and its data.
Mitigation Recommendations
Upgrade AlanWeb SCADA to version 9.8.5 or later, where this missing authorization vulnerability has been fixed. No other mitigation guidance is provided; patching is the recommended action.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-03-26T09:40:20.576Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 69d779fb1cc7ad14da954bdf
Added to database: 04/09/2026, 10:05:47 UTC
Last enriched: 08/13/2026, 13:05:43 UTC
Last updated: 09/14/2026, 22:01:33 UTC
Views: 168
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.