Junglewise Threat Intelligence

CVE-2026-44469: CODESYS Development System privilege escalation via TOCTOU race condition

CVE-2026-44469 · Severity: high · CVSS 7.8 · Published 2026-05-26

Vendors: CODESYS.

Executive brief

The CODESYS Development System, used for programming industrial controllers, contains a security flaw in its installation process. When an administrator installs software packages, the system creates temporary folders with weak security settings. This allows a person with limited access to the computer to swap legitimate installation files with malicious ones, potentially gaining full administrative control over the workstation.

Technical details

The CODESYS Development System (specifically the PackageManager and IPM components) suffers from an incorrect default permission vulnerability (CWE-276) during the installation of packages or add-ons. When running with administrative privileges, the software extracts installation files into a temporary directory that is accessible to low-privileged local users. An attacker can exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition to replace digitally verified files with malicious payloads after verification but before the final installation step. This allows the attacker to execute arbitrary code with elevated administrative privileges. The issue is resolved in version 3.5.22.20.

Affected products

  • CODESYS Development System < 3.5.22.20

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory
  • 2026-05-26: patched: Fixed in version 3.5.22.20

References

Related threats