Junglewise Threat Intelligence

CVE-2026-12663: Rockwell Automation ControlFLASH improper access control in installer

CVE-2026-12663 · Severity: info · CVSS 7.3 · Published 2026-09-01

Vendors: Rockwell Automation.

Executive brief

ControlFLASH is a firmware management utility used by industrial automation engineers to update firmware on Allen-Bradley controllers and other devices. The installer incorrectly grants write permissions to all users on the installation directory, allowing any local user to replace executable files with malicious code and execute arbitrary commands at the logged-in user's privilege level.

Technical details

The vulnerability is an improper access control issue (CWE-306) in the ControlFLASH installer. During installation, the utility grants write permissions to the "Everyone" group on the installation directory (C:\Program Files (x86)\ControlFLASH\0001), enabling local privilege escalation or code injection. An attacker with local file system access can replace legitimate executables or DLLs in the installation folder with malicious ones. Exploitation requires local access to the system and affects users running at the privilege level of the logged-in account. The vulnerability was found internally during routine testing. A fix is available in ControlFLASH version 15.08 and later; affected users on v15.07 and prior can manually remediate by removing the Everyone group's permissions on the installation directory.

Affected products

  • Rockwell Automation ControlFLASH 15.07 and prior

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Fix available in version 15.08

References