CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Rockwell Automation ThinManager

criticalCVE-2026-11917
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The following versions of Rockwell Automation ThinManager are affected: ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2 CVSS Vendor Equipment Vulnerabilities v3 8.1 Rockwell Automation Rockwell Automation ThinManager Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-11917 A path traversal security issue exists within Rockwell Automation ThinManager software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory. View CVE Details Affected Products Rockwell Automation ThinManager Vendor: Rockwell Automation Product Version: Rockwell Automation ThinManager: >=13.0.0|<13.0.7, Rockwell Automation ThinManager: >=13.1.0|<13.1.5, Rockwell Automation ThinManager: >=13.2.0|<13.2.4, Rockwell Automation ThinManager: >=14.0.0|<14.0.2 Product Status: known_affected Remediations Mitigation Users using the affected software, should upgrade to one of the corrected versions as follows: Vendor fix ThinManager Versions 13.0.0 - 13.0.7 --> 13.0.8 Vendor fix ThinManager Versions 13.1.0 - 13.1.5 --> 13.1.6 Vendor fix ThinManager Versions 13.2.0 - 13.2.4 --> 13.2.5 Vendor fix ThinManager Versions 14.0.0 - 14.0.2 --> 14.0.3 Mitigation Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices. https://support.roc

CSIRTS triage

vendor: Rockwell Automationproduct: ThinManagerPath traversalaffected: ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2
What
Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories.
Who is affected
Authenticated users of the affected versions of Rockwell Automation ThinManager are at risk.
Urgency
Remediation is critical due to the potential for unauthorized file access and the high severity rating.
Action
Update to the latest version of ThinManager to mitigate the vulnerability.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch ThinManager

Get an email when a new ThinManager advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-07-23
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-11917coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Rockwell Automation ThinManager

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Cybersecurity Advisories