PatchSiren cyber security CVE debrief
CVE-2026-9108 Rockwell Automation CVE debrief
A path traversal security issue exists within Studio 5000 Logix Designer due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.
- Vendor
- Rockwell Automation
- Product
- Studio 5000 Logix Designer
- CVSS
- MEDIUM 6.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-21
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-21
Who should care
Organizations using Rockwell Automation Studio 5000 Logix Designer, especially those in industrial control systems environments, should prioritize patching, especially if using affected versions. Operators, platform administrators, vulnerability management teams, and security teams should be aware of the potential impact and take necessary precautions to prevent exploitation.
Technical summary
The path traversal vulnerability in Studio 5000 Logix Designer allows an attacker to craft a malicious ACD project file, potentially leading to code execution. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. Organizations using Rockwell Automation Studio 5000 Logix Designer, especially in industrial control systems environments, should prioritize patching, particularly if using affected versions. Operators, platform administrators, vulnerability management teams, and security teams should be aware of the potential impact and take necessary precautions to prevent exploitation, including verifying affected product deployments, reviewing official advisories, and planning vendor-supported updates or mitigations.
Defensive priority
Organizations using Rockwell Automation Studio 5000 Logix Designer should prioritize patching, especially if using affected versions.
Recommended defensive actions
- Upgrade to Studio 5000 Logix Designer: V37.00, 36.01, 35.02, 34.04, 33.04, 32.05
- Implement Rockwell Automation's security best practices
- Monitor for suspicious ACD project file activity
- Restrict access to ACD project files
- Regularly review and update system configurations
Evidence notes
The CVE record and CISA CSAF advisory provide details on the path traversal vulnerability in Studio 5000 Logix Designer. Evidence is based on official records from Rockwell Automation and CISA. The vulnerability allows an attacker to craft a malicious ACD project file, potentially leading to code execution. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
Official resources
-
CVE-2026-9108 CVE record
CVE.org
-
CVE-2026-9108 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T06:00:00.000Z and has not been modified since then.