CVE Database
/

CVE-2026-34184

Back to search

CVE-2026-34184

Published: Apr 9, 2026

Modified: Apr 9, 2026

PUBLISHED

Description

Hydrosystem Control System does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database.This issue was fixed in Hydrosystem Control System version 9.8.5

VendorProductVersions

Hydrosystem

Control System

affected
0 - < 9.8.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now