CVE-2026-4901 PUBLISHED

Insertion of Sesitive Information into Log File in Hydrosystem Control System

Assigner: CERT-PL
Reserved: 26.03.2026 Published: 09.04.2026 Updated: 09.04.2026

Hydrosystem Control System saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user.This issue was fixed in Hydrosystem Control System version 9.8.5

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Hydrosystem
Product Control System
Versions Default: unaffected
  • affected from 0 to 9.8.5 (excl.)

Credits

  • Jarosław "Jahrek" Kamiński - Securitum finder

References

Problem Types

  • CWE-532: Insertion of Sensitive Information into Log File CWE