Hydrosystem Control System saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user.This issue was fixed in Hydrosystem Control System version 9.8.5
References
| Link | Resource |
|---|---|
| https://cert.pl/posts/2026/04/CVE-2026-4901/ | Vendor Advisory |
| https://www.hydrosystem.poznan.pl/ | Product |
Configurations
History
20 Apr 2026, 17:05
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Hydrosystem.poznan
Hydrosystem.poznan control System |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| References | () https://cert.pl/posts/2026/04/CVE-2026-4901/ - Vendor Advisory | |
| References | () https://www.hydrosystem.poznan.pl/ - Product | |
| CPE | cpe:2.3:a:hydrosystem.poznan:control_system:*:*:*:*:*:*:*:* |
09 Apr 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-09 10:16
Updated : 2026-04-20 17:05
NVD link : CVE-2026-4901
Mitre link : CVE-2026-4901
CVE.ORG link : CVE-2026-4901
JSON object : View
Products Affected
hydrosystem.poznan
- control_system
CWE
CWE-532
Insertion of Sensitive Information into Log File
