PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-27668 Siemens CVE debrief

CVE-2026-27668 describes an authenticated privilege-escalation issue in Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) versions before 5.8. The advisory states that User Administrators are allowed to administer groups they belong to, which can let a User Administrator elevate their own privileges and grant themselves access to any device group at any access level. The supplied CVSS v3.1 score is 8.8 (HIGH), reflecting network exposure, low attack complexity, and high impact if an attacker already has a User Administrator account.

Vendor
Siemens
Product
RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P)
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-14
Original CVE updated
2026-04-21
Advisory published
2026-04-14
Advisory updated
2026-04-21

Who should care

OT/ICS operators running Siemens RUGGEDCOM CROSSBOW SAM-P before v5.8, administrators managing User Administrator accounts, and security teams responsible for access-control boundaries in industrial environments.

Technical summary

The issue is an access-control flaw: a role intended to administer only certain groups can be used by an authenticated User Administrator to extend privileges beyond the intended boundary. The affected product scope in the supplied advisory is Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) versions earlier than 5.8. Siemens remediation is to update to V5.8 or later.

Defensive priority

High—prioritize patching to V5.8 or later during the next maintenance window, especially where SAM-P governs access to production OT devices.

Recommended defensive actions

  • Upgrade Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) to V5.8 or later.
  • Identify all deployments of SAM-P and confirm which versions are below 5.8.
  • Review User Administrator assignments and remove unnecessary privileged accounts.
  • Audit device-group permissions and recent administrative changes for unexpected access expansion.
  • Apply OT defense-in-depth and least-privilege controls around management access as recommended by CISA and Siemens.

Evidence notes

The supplied CISA CSAF source and linked Siemens advisories state that this vulnerability affects Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) vers:intdot/<5.8 and that the vendor fix is V5.8 or later. The advisory text explicitly says User Administrators can administer groups they belong to, enabling privilege escalation and access to any device group at any access level. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H with a score of 8.8 (HIGH). The source timeline shows publication on 2026-04-14 and republication on 2026-04-21; no KEV entry is provided in the supplied data.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-27668 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-27668

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-27668 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-27668

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-741509.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-741509.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.