Executive brief
Siemens License Server (SLS) is a central server application that manages software licensing for various Siemens industrial and CAD/CAM products. A path traversal vulnerability allows unauthenticated remote attackers to access arbitrary files on the affected system, potentially exposing sensitive configuration data, credentials, or proprietary information.
Technical details
CVE-2026-69109 is a path traversal vulnerability (CWE-35) in Siemens License Server caused by insufficient input sanitization. The flaw is remotely exploitable over the network without requiring authentication or user interaction (CVSS v3.1 AV:N/AC:L/PR:N/UI:N), allowing an attacker to traverse the filesystem and read arbitrary files. The vulnerability affects all versions prior to V5.3. Siemens has released a security update (V5.3 or later) to remediate the issue.
Affected products
- Siemens License Server (SLS) All versions < V5.3
Timeline
- 2026-08-11: disclosed