Junglewise Threat Intelligence

CVE-2026-69109: Siemens License Server path traversal

CVE-2026-69109 · Severity: high · CVSS 7.5 · Published 2026-08-11

Vendors: Siemens.

Executive brief

Siemens License Server (SLS) is a central server application that manages software licensing for various Siemens industrial and CAD/CAM products. A path traversal vulnerability allows unauthenticated remote attackers to access arbitrary files on the affected system, potentially exposing sensitive configuration data, credentials, or proprietary information.

Technical details

CVE-2026-69109 is a path traversal vulnerability (CWE-35) in Siemens License Server caused by insufficient input sanitization. The flaw is remotely exploitable over the network without requiring authentication or user interaction (CVSS v3.1 AV:N/AC:L/PR:N/UI:N), allowing an attacker to traverse the filesystem and read arbitrary files. The vulnerability affects all versions prior to V5.3. Siemens has released a security update (V5.3 or later) to remediate the issue.

Affected products

  • Siemens License Server (SLS) All versions < V5.3

Timeline

  • 2026-08-11: disclosed

References

Related threats