CVE-2026-4901

Summary

AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user.

This issue was fixed in AlanWeb SCADA version 9.8.5

Affected Software

VendorProductVersion RangeStatus
Control SystemAlanWeb SCADA0 < 9.8.5affected

Weaknesses

  • CWE-532: CWE-532: Insertion of Sensitive Information into Log File

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References