Rockwell Automation ThinManager
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The following versions of Rockwell Automation ThinManager are affected: ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2 CVSS Vendor Equipment Vulnerabilities v3 8.1 Rockwell Automation Rockwell Automation ThinManager Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-11917 A path traversal security issue exists within Rockwell Automation ThinManager software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory. View CVE Details Affected Products Rockwell Automation ThinManager Vendor: Rockwell Automation Product Version: Rockwell Automation ThinManager: >=13.0.0|<13.0.7, Rockwell Automation ThinManager: >=13.1.0|<13.1.5, Rockwell Automation ThinManager: >=13.2.0|<13.2.4, Rockwell Automation ThinManager: >=14.0.0|<14.0.2 Product Status: known_affected Remediations Mitigation Users using the affected software, should upgrade to one of the corrected versions as follows: Vendor fix ThinManager Versions 13.0.0 - 13.0.7 --> 13.0.8 Vendor fix ThinManager Versions 13.1.0 - 13.1.5 --> 13.1.6 Vendor fix ThinManager Versions 13.2.0 - 13.2.4 --> 13.2.5 Vendor fix ThinManager Versions 14.0.0 - 14.0.2 --> 14.0.3 Mitigation Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices. https://support.roc
CSIRTS triage
- What
- Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories.
- Who is affected
- Authenticated users of the affected versions of Rockwell Automation ThinManager are at risk.
- Urgency
- Remediation is critical due to the potential for unauthorized file access and the high severity rating.
- Action
- Update to the latest version of ThinManager to mitigate the vulnerability.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ThinManager
Get an email when a new ThinManager advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-119170.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-11917 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Rockwell Automation ThinManager
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalMZ Automation GmbH libiec618502026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30