Security Advisory

CVE-2026-4901

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-09 09:40:59
Last updated 2026-08-13 09:21:11
Assigner CERT-PL
CVSS score 6.9
State PUBLISHED

Description

AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user. This issue was fixed in AlanWeb SCADA version 9.8.5