Description
Hydrosystem Control System saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user.This issue was fixed in Hydrosystem Control System version 9.8.5
Problem types
CWE-532: Insertion of Sensitive Information into Log File
Product status
Any version before 9.8.5
Credits
Jarosław "Jahrek" Kamiński - Securitum
References
cert.pl/posts/2026/04/CVE-2026-4901/
www.hydrosystem.poznan.pl/