CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-69109

criticalCVSS 7.5covered by 3 sourcesfirst seen 2026-08-11
View CSAF Summary Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version. The following versions of Siemens License Server (SLS) are affected: Siemens License Server (SLS) vers:intdot/<5.1, vers:intdot/<5.3 (CVE-2026-69108, CVE-2026-69109) CVSS Vendor Equipment Vulnerabilities v3 7.5 Siemens Siemens License Server (SLS) Incorrect Permission Assignment for Critical Resource, Path Traversal: '.../...//' Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-69108 The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise. View CVE Details Affected Products Siemens License Server (SLS) Vendor: Siemens Product Version: Siemens License Server (SLS) < V5.1 Product Status: known_affected Remediations Vendor fix Update to V5.1 or later version https://support.sw.siemens.com/product/1586485382/ Relevant CWE: CWE-732 Incorrect Permission Assignment for Critical Resource Metrics CVSS Version Base Score Base Severity Vector String 3.1 6 MEDIUM CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N CVE-2026-69109 The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application. View CVE Details Affected Products Siemens License Server (SLS) Vendor: Siemens Product Version: Siemens License Server (SLS) < V5.3 Product Status: known_affected Remediations Vendor fix Update to V5.3 or later version https://support.sw.siemens.com/product/1586485382/ Relevan

CSIRTS triage

What
Multiple vulnerabilities including local privilege escalation and path traversal allow elevation of privileges and reading arbitrary files on the system.
Who is affected
Siemens License Server versions prior to 5.1 and 5.3 in information technology and critical infrastructure deployments.
Urgency
Immediate; critical severity with CVSS 7.5 allowing privilege escalation and arbitrary file access.
Action
Update Siemens License Server to version 5.3 or later as recommended by Siemens.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-69109

Get an email if CVE-2026-69109 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-69109

CVE.org record

Embed the live status

CVE-2026-69109 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-69109 status](https://www.csirts.com/badge/CVE-2026-69109)](https://www.csirts.com/cve/CVE-2026-69109)