Siemens License Server (SLS)
View CSAF Summary Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version. The following versions of Siemens License Server (SLS) are affected: Siemens License Server (SLS) vers:intdot/<5.1, vers:intdot/<5.3 (CVE-2026-69108, CVE-2026-69109) CVSS Vendor Equipment Vulnerabilities v3 7.5 Siemens Siemens License Server (SLS) Incorrect Permission Assignment for Critical Resource, Path Traversal: '.../...//' Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-69108 The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise. View CVE Details Affected Products Siemens License Server (SLS) Vendor: Siemens Product Version: Siemens License Server (SLS) < V5.1 Product Status: known_affected Remediations Vendor fix Update to V5.1 or later version https://support.sw.siemens.com/product/1586485382/ Relevant CWE: CWE-732 Incorrect Permission Assignment for Critical Resource Metrics CVSS Version Base Score Base Severity Vector String 3.1 6 MEDIUM CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N CVE-2026-69109 The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application. View CVE Details Affected Products Siemens License Server (SLS) Vendor: Siemens Product Version: Siemens License Server (SLS) < V5.3 Product Status: known_affected Remediations Vendor fix Update to V5.3 or later version https://support.sw.siemens.com/product/1586485382/ Relevan
CSIRTS triage
- What
- Multiple vulnerabilities including local privilege escalation and path traversal allow elevation of privileges and reading arbitrary files on the system.
- Who is affected
- Siemens License Server versions prior to 5.1 and 5.3 in information technology and critical infrastructure deployments.
- Urgency
- Immediate; critical severity with CVSS 7.5 allowing privilege escalation and arbitrary file access.
- Action
- Update Siemens License Server to version 5.3 or later as recommended by Siemens.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch License Server (SLS)
Get an email when a new License Server (SLS) advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-07
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-691080.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-691090.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69108 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-69109 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-69109: A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The…nvd
- mediumCVE-2026-69108: A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The…nvd
- unknownNCSC-2026-0282 [1.00] [M/H] Vulnerabilities fixed in Siemens productsncsc-nl
Recent advisories for Siemens License Server
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
More from CISA Cybersecurity Advisories
- criticalJohnson Controls Metasys2026-08-13
- criticalSiemens Siveillance Video2026-08-13
- criticalFlow Neuroscience FL-1002026-08-13
- criticalSiemens LOGO! Soft Comfort2026-08-13
- criticalJohnson Controls Inc. Airwall2026-08-13