VORANT. Threat Intelligence Sign in Get the full feed

Hydrosystem Control flaws risk full takeover

medium vulnerability infrastructure

Three vulnerabilities in Hydrosystem Control System let attackers steal logged credentials, bypass authorization, and inject SQL to potentially seize full database control.

CERT Polska coordinated disclosure of three vulnerabilities in Hydrosystem Control System, an industrial control platform. CVE-2026-4901 causes the system to log sensitive data including user credentials, which combined with CVE-2026-34184's missing directory authorization could let an unauthenticated attacker read those logs and harvest login credentials. CVE-2026-34184 also allows unauthorized attackers to read and execute files in unprotected directories, including running arbitrary PHP scripts directly against the connected database.

CVE-2026-34185 describes widespread SQL injection across most scripts and input parameters, allowing an authenticated attacker to run arbitrary SQL commands and potentially gain full control of the backend database. Chained together, these three issues present a path from unauthenticated log access to credential theft, unauthorized file execution, and full database compromise. The vendor has fixed all three issues in version 9.8.5, and the report credits researcher Jarosław Kamiński of Securitum for the responsible disclosure. No active exploitation has been reported.

Mentioned in this report

Vulnerabilities CVE-2026-34184CVE-2026-34185CVE-2026-4901

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-4901

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free