CVE-2026-9127

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*:*
cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*:*
cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*:*
cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:35.00:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-14 16:17

Updated : 2026-08-25 16:57


NVD link : CVE-2026-9127

Mitre link : CVE-2026-9127

CVE.ORG link : CVE-2026-9127


JSON object : View

Products Affected

rockwellautomation

  • studio_5000_logix_designer
CWE
CWE-863

Incorrect Authorization