THREAT OPS › Threat News › [NVD] CVE-2026-34185 (HIGH 8.8) — AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.
This issue was fixed in AlanWeb SCADA vers
[NVD] CVE-2026-34185 (HIGH 8.8) — AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database. This issue was fixed in AlanWeb SCADA vers
CVE-2026-34185 CVSS: 8.8 HIGH Published: 2026-04-09T10:16:22.260
AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.
This issue was fixed in AlanWeb SCADA version 9.8.5
Indicators of compromise
- CVE-2026-34185cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-34185