PatchSiren cyber security CVE debrief
CVE-2026-27668 Siemens CVE debrief
CVE-2026-27668 describes an authenticated privilege-escalation issue in Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) versions before 5.8. The advisory states that User Administrators are allowed to administer groups they belong to, which can let a User Administrator elevate their own privileges and grant themselves access to any device group at any access level. The supplied CVSS v3.1 score is 8.8 (HIGH), reflecting network exposure, low attack complexity, and high impact if an attacker already has a User Administrator account.
- Vendor
- Siemens
- Product
- RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P)
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-14
- Original CVE updated
- 2026-04-21
- Advisory published
- 2026-04-14
- Advisory updated
- 2026-04-21
Who should care
OT/ICS operators running Siemens RUGGEDCOM CROSSBOW SAM-P before v5.8, administrators managing User Administrator accounts, and security teams responsible for access-control boundaries in industrial environments.
Technical summary
The issue is an access-control flaw: a role intended to administer only certain groups can be used by an authenticated User Administrator to extend privileges beyond the intended boundary. The affected product scope in the supplied advisory is Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) versions earlier than 5.8. Siemens remediation is to update to V5.8 or later.
Defensive priority
High—prioritize patching to V5.8 or later during the next maintenance window, especially where SAM-P governs access to production OT devices.
Recommended defensive actions
- Upgrade Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) to V5.8 or later.
- Identify all deployments of SAM-P and confirm which versions are below 5.8.
- Review User Administrator assignments and remove unnecessary privileged accounts.
- Audit device-group permissions and recent administrative changes for unexpected access expansion.
- Apply OT defense-in-depth and least-privilege controls around management access as recommended by CISA and Siemens.
Evidence notes
The supplied CISA CSAF source and linked Siemens advisories state that this vulnerability affects Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) vers:intdot/<5.8 and that the vendor fix is V5.8 or later. The advisory text explicitly says User Administrators can administer groups they belong to, enabling privilege escalation and access to any device group at any access level. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H with a score of 8.8 (HIGH). The source timeline shows publication on 2026-04-14 and republication on 2026-04-21; no KEV entry is provided in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-27668 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-27668
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-27668 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-27668
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-741509.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-741509.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.