CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Siemens License Server (SLS)

criticalCVE-2026-69108CVE-2026-69109
View CSAF Summary Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version. The following versions of Siemens License Server (SLS) are affected: Siemens License Server (SLS) vers:intdot/<5.1, vers:intdot/<5.3 (CVE-2026-69108, CVE-2026-69109) CVSS Vendor Equipment Vulnerabilities v3 7.5 Siemens Siemens License Server (SLS) Incorrect Permission Assignment for Critical Resource, Path Traversal: '.../...//' Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-69108 The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise. View CVE Details Affected Products Siemens License Server (SLS) Vendor: Siemens Product Version: Siemens License Server (SLS) < V5.1 Product Status: known_affected Remediations Vendor fix Update to V5.1 or later version https://support.sw.siemens.com/product/1586485382/ Relevant CWE: CWE-732 Incorrect Permission Assignment for Critical Resource Metrics CVSS Version Base Score Base Severity Vector String 3.1 6 MEDIUM CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N CVE-2026-69109 The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application. View CVE Details Affected Products Siemens License Server (SLS) Vendor: Siemens Product Version: Siemens License Server (SLS) < V5.3 Product Status: known_affected Remediations Vendor fix Update to V5.3 or later version https://support.sw.siemens.com/product/1586485382/ Relevan

CSIRTS triage

What
Multiple vulnerabilities including local privilege escalation and path traversal allow elevation of privileges and reading arbitrary files on the system.
Who is affected
Siemens License Server versions prior to 5.1 and 5.3 in information technology and critical infrastructure deployments.
Urgency
Immediate; critical severity with CVSS 7.5 allowing privilege escalation and arbitrary file access.
Action
Update Siemens License Server to version 5.3 or later as recommended by Siemens.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch License Server (SLS)

Get an email when a new License Server (SLS) advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-08-13
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-07

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-69108coverage & exploitation statusNVD · CVE.org
CVE-2026-69109coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Siemens License Server

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Cybersecurity Advisories