Executive brief
Rockwell Automation ThinManager is a centralized management platform used to control industrial visualization and thin client devices in manufacturing environments. A security flaw in the software's programming interface allows an authorized user to save files into restricted system folders where they do not belong. This could allow an attacker to disrupt operations or compromise the underlying server by overwriting critical system files.
Technical details
A path traversal vulnerability (CWE-22) exists in the API of Rockwell Automation ThinManager. The root cause is improper validation of file paths during file save operations, which fails to restrict writes to the application's intended directory. An authenticated attacker can exploit this by providing manipulated path sequences to write arbitrary files to restricted system directories. This can lead to a loss of integrity or availability if critical system files are overwritten. The vulnerability is addressed in versions 13.0.8, 13.1.6, 13.2.5, and 14.0.3.
Affected products
- Rockwell Automation ThinManager 13.0.0 – 13.0.7, 13.1.0 – 13.1.5, 13.2.0 – 13.2.4, 14.0.0 – 14.0.2
Timeline
- 2026-07-14: advisory
- 2026-07-14: patched