CVE-2026-11917
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The following versions of Rockwell Automation ThinManager are affected: ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2 CVSS Vendor Equipment Vulnerabilities v3 8.1 Rockwell Automation Rockwell Automation ThinManager Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-11917 A path traversal security issue exists within Rockwell Automation ThinManager software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory. View CVE Details Affected Products Rockwell Automation ThinManager Vendor: Rockwell Automation Product Version: Rockwell Automation ThinManager: >=13.0.0|<13.0.7, Rockwell Automation ThinManager: >=13.1.0|<13.1.5, Rockwell Automation ThinManager: >=13.2.0|<13.2.4, Rockwell Automation ThinManager: >=14.0.0|<14.0.2 Product Status: known_affected Remediations Mitigation Users using the affected software, should upgrade to one of the corrected versions as follows: Vendor fix ThinManager Versions 13.0.0 - 13.0.7 --> 13.0.8 Vendor fix ThinManager Versions 13.1.0 - 13.1.5 --> 13.1.6 Vendor fix ThinManager Versions 13.2.0 - 13.2.4 --> 13.2.5 Vendor fix ThinManager Versions 14.0.0 - 14.0.2 --> 14.0.3 Mitigation Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices. https://support.roc
CSIRTS triage
- What
- Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories.
- Who is affected
- Authenticated users of the affected versions of Rockwell Automation ThinManager are at risk.
- Urgency
- Remediation is critical due to the potential for unauthorized file access and the high severity rating.
- Action
- Update to the latest version of ThinManager to mitigate the vulnerability.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-11917
Get an email if CVE-2026-11917 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Advisory coverage (2)
- criticalRockwell Automation ThinManagercisa · 2026-07-23
- unknownCVE-2026-11917: A path traversal security issue exists within Rockwell Automation ThinManager® software due to…nvd · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-11917)