BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

News Vulnerability
VulnerabilityCISA·7d ago

Rockwell Automation Studio 5000 Logix Designer

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-10.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. /strong /p p The following versions of Rockwell Automation Studio 5000 Logix Designer are affected: /p ul li Studio 5000 Logix Designer V36.00 (CVE-2026-9108) /li li Studio 5000 Logix Designer V35.00 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) /li li Studio 5000 Logix Designer V35.01 (CVE-2026-9108) /li li Studio 5000 Logix Designer gt;=V34.00| lt;=V34.03 (CVE-2026-9108) /li li Studio 5000 Logix Designer gt;=V33.00| lt;=V33.03 (CVE-2026-9108) /li li Studio 5000 Logix Designer gt;=V32.00| lt;=V32.04 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) /li li Studio 5000 Logix Designer V34.00 (CVE-2026-9127) /li li Studio 5000 Logix Designer V34.01 (CVE-2026-9127) /li li Studio 5000 Logix Designer V33.00 (CVE-2026-9127) /li li Studio 5000 Logix Designer V33.02 (CVE-2026-9127) /li li Studio 5000 Logix Designer gt;=V34.00| lt;=V34.02 (CVE-2026-9128) /li li Studio 5000 Logix Designer gt;=V33.00| lt;=V33.02 (CVE-2026-9128) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation Studio 5000 Logix Designer /td td Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Incorrect Authorization, Unquoted Search Path or Element /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-9108 /a /h3 div class="csaf-accordion-content" p A path traversal security issue exists within Studio 5000 Logix Designer due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-9108" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation Stud

Sign in to read the full article

Create a free account to access all news, downloads, and community features

Originally published by CISA

Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10

This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.

Shared on IT-Hub by admin