A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.
References
| Link | Resource |
|---|---|
| https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1783.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-14 16:17
Updated : 2026-08-25 16:57
NVD link : CVE-2026-9127
Mitre link : CVE-2026-9127
CVE.ORG link : CVE-2026-9127
JSON object : View
Products Affected
rockwellautomation
- studio_5000_logix_designer
CWE
CWE-863
Incorrect Authorization
