Junglewise Threat Intelligence

CVE-2026-44468: CODESYS Development System privilege escalation via insecure permissions

CVE-2026-44468 · Severity: high · CVSS 7.8 · Published 2026-05-26

Vendors: CODESYS.

Executive brief

CODESYS Development System is a software suite used for programming industrial controllers. A security flaw in its installation process allows a user with limited access to a computer to interfere with administrative software updates. By modifying temporary installation files, an attacker can force the system to install malicious components, effectively gaining full administrative control over the workstation.

Technical details

The CODESYS Development System PackageManager and IPM components create temporary directories with insecure default permissions (CWE-276) when running with administrative privileges. A low-privileged local attacker can modify a temporary bootstrap file within these directories that defines which components are to be installed. Because the installation process executes in an elevated context, the manipulated file allows the attacker to force the deployment of arbitrary, potentially malicious components, leading to local privilege escalation. This vulnerability is fixed in version 3.5.22.20.

Affected products

  • CODESYS Development System < 3.5.22.20

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory
  • 2026-05-26: patched: Fixed in version 3.5.22.20

References

Related threats