Hydrosystem Control System does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database.This issue was fixed in Hydrosystem Control System version 9.8.5
PUBLISHED5.2CWE-862
Missing Authorization in Hydrosystem Control System
Problem type
Affected products
Hydrosystem
Control System
< 9.8.5 - AFFECTED
References
cert.pl
https://cert.pl/posts/2026/04/CVE-2026-4901/
hydrosystem.poznan.pl
https://www.hydrosystem.poznan.pl/
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-34184Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-34184",
"assignerOrgId": "4bb8329e-dd38-46c1-aafb-9bf32bcb93c6",
"assignerShortName": "CERT-PL",
"dateUpdated": "2026-04-09T11:51:07.882Z",
"dateReserved": "2026-03-26T09:40:20.576Z",
"datePublished": "2026-04-09T09:41:08.526Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "4bb8329e-dd38-46c1-aafb-9bf32bcb93c6",
"shortName": "CERT-PL",
"dateUpdated": "2026-04-09T09:41:08.526Z"
},
"title": "Missing Authorization in Hydrosystem Control System",
"descriptions": [
{
"lang": "en",
"value": "Hydrosystem Control System does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database.This issue was fixed in Hydrosystem Control System version 9.8.5",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "Hydrosystem Control System does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database.<p>This issue was fixed in Hydrosystem Control System version 9.8.5</p>"
}
]
}
],
"affected": [
{
"vendor": "Hydrosystem",
"product": "Control System",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThan": "9.8.5"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-862: Missing Authorization",
"cweId": "CWE-862",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://cert.pl/posts/2026/04/CVE-2026-4901/",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://www.hydrosystem.poznan.pl/",
"tags": [
"product"
]
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Jarosław \"Jahrek\" Kamiński - Securitum",
"type": "finder"
}
]
},
"adp": [
{
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2026-04-09T11:51:07.882Z"
},
"title": "CISA ADP Vulnrichment",
"metrics": [
{}
]
}
]
}
}