MEDIUMVulnerability
CVE-2026-4901
AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user. This issue was fixed in AlanWeb SCADA version 9.8.5
Properties
- severity
- MEDIUM
- score
- 6.5
- cve_id
- CVE-2026-4901
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- published_at
- 2026-04-09T10:16:22.543
- last_modified
- 2026-08-13T10:17:13.380
Related Entities (3)
AFFECTS_PRODUCT (1)
→[Product]
HAS_WEAKNESS (1)
→[Weakness]Insertion of Sensitive Information into Log File
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph