CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-9108

criticalcovered by 3 sourcesfirst seen 2026-07-14
View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions of Rockwell Automation Studio 5000 Logix Designer are affected: Studio 5000 Logix Designer V36.00 (CVE-2026-9108) Studio 5000 Logix Designer V35.00 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) Studio 5000 Logix Designer V35.01 (CVE-2026-9108) Studio 5000 Logix Designer >=V34.00|<=V34.03 (CVE-2026-9108) Studio 5000 Logix Designer >=V33.00|<=V33.03 (CVE-2026-9108) Studio 5000 Logix Designer >=V32.00|<=V32.04 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) Studio 5000 Logix Designer V34.00 (CVE-2026-9127) Studio 5000 Logix Designer V34.01 (CVE-2026-9127) Studio 5000 Logix Designer V33.00 (CVE-2026-9127) Studio 5000 Logix Designer V33.02 (CVE-2026-9127) Studio 5000 Logix Designer >=V34.00|<=V34.02 (CVE-2026-9128) Studio 5000 Logix Designer >=V33.00|<=V33.02 (CVE-2026-9128) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation Studio 5000 Logix Designer Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Incorrect Authorization, Unquoted Search Path or Element Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9108 A path traversal security issue exists within Studio 5000 Logix Designer due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution. View CVE Details Affected Prod

CSIRTS triage

vendor: Rockwell Automationproduct: Studio 5000 Logix DesignerOtheraffected: V36.00, V35.00, V35.01, >=V34.00|<=V34.03, >=V33.00|<=V33.03, >=V32.00|<=V32.04
What
Multiple vulnerabilities could allow local attackers to execute arbitrary code.
Who is affected
Deployments of Studio 5000 Logix Designer across specified versions.
Urgency
Remediation is urgent due to the critical nature of the vulnerabilities.
Action
Update to the latest version of Studio 5000 Logix Designer.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-9108

Get an email if CVE-2026-9108 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-9108

CVE.org record

Embed the live status

CVE-2026-9108 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-9108 status](https://www.csirts.com/badge/CVE-2026-9108)](https://www.csirts.com/cve/CVE-2026-9108)