Hydrosystem Control System saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user.This issue was fixed in Hydrosystem Control System version 9.8.5
History

Thu, 09 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Apr 2026 10:00:00 +0000

Type Values Removed Values Added
Description Hydrosystem Control System saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user.This issue was fixed in Hydrosystem Control System version 9.8.5
Title Insertion of Sesitive Information into Log File in Hydrosystem Control System
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-04-09T11:51:48.409Z

Reserved: 2026-03-26T14:59:49.077Z

Link: CVE-2026-4901

cve-icon Vulnrichment

Updated: 2026-04-09T11:51:45.466Z

cve-icon NVD

Status : Received

Published: 2026-04-09T10:16:22.543

Modified: 2026-04-09T10:16:22.543

Link: CVE-2026-4901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.