PatchSiren cyber security CVE debrief
CVE-2026-9108 Rockwell Automation CVE debrief
A path traversal security issue exists within Studio 5000 Logix Designer due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.
- Vendor
- Rockwell Automation
- Product
- Studio 5000 Logix Designer
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-08-25
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-08-25
Who should care
Organizations using Rockwell Automation Studio 5000 Logix Designer, especially those in industrial control systems environments, should prioritize patching, especially if using affected versions. Operators, platform administrators, vulnerability management teams, and security teams should be aware of the potential impact and take necessary precautions to prevent exploitation.
Technical summary
The path traversal vulnerability in Studio 5000 Logix Designer allows an attacker to craft a malicious ACD project file, potentially leading to code execution. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. Organizations using Rockwell Automation Studio 5000 Logix Designer, especially in industrial control systems environments, should prioritize patching, particularly if using affected versions. Operators, platform administrators, vulnerability management teams, and security teams should be aware of the potential impact and take necessary precautions to prevent exploitation, including verifying affected product deployments, reviewing official advisories, and planning vendor-supported updates or mitigations.
Defensive priority
Organizations using Rockwell Automation Studio 5000 Logix Designer should prioritize patching, especially if using affected versions.
Recommended defensive actions
- Upgrade to Studio 5000 Logix Designer: V37.00, 36.01, 35.02, 34.04, 33.04, 32.05
- Implement Rockwell Automation's security best practices
- Monitor for suspicious ACD project file activity
- Restrict access to ACD project files
- Regularly review and update system configurations
Evidence notes
The CVE record and CISA CSAF advisory provide details on the path traversal vulnerability in Studio 5000 Logix Designer. Evidence is based on official records from Rockwell Automation and CISA. The vulnerability allows an attacker to craft a malicious ACD project file, potentially leading to code execution. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9108 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9108
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9108 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9108
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.