THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-34185 (HIGH 8.8) — AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database. This issue was fixed in AlanWeb SCADA vers

[NVD] CVE-2026-34185 (HIGH 8.8) — AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database. This issue was fixed in AlanWeb SCADA vers

lownvdPublished 2026-04-09

CVE-2026-34185 CVSS: 8.8 HIGH Published: 2026-04-09T10:16:22.260

AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.

This issue was fixed in AlanWeb SCADA version 9.8.5

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-34185