Junglewise Threat Intelligence

CVE-2026-9108: Rockwell Automation Studio 5000 Logix Designer path traversal in ACD files

CVE-2026-9108 · Severity: info · CVSS 6.7 · Published 2026-07-14

Technologies: Rockwell Automation Studio 5000 Logix Designer. Vendors: Rockwell Automation.

Executive brief

Rockwell Automation Studio 5000 Logix Designer, a software suite used to program industrial controllers, is vulnerable to a path traversal flaw. An attacker can create a malicious project file that, when opened by a user, writes files to unauthorized locations on the computer. This could allow an attacker to gain control over the workstation used to manage industrial automation systems, potentially disrupting operations or compromising sensitive configurations.

Technical details

A path traversal vulnerability (CWE-22) exists in Studio 5000 Logix Designer due to improper validation of file paths within ACD project files. When a user opens a specially crafted ACD file, the software fails to sanitize embedded filenames, allowing path traversal sequences (e.g., ../) to escape the intended extraction directory. An attacker can exploit this to write arbitrary files to sensitive locations on the local filesystem. If an attacker overwrites system files or places executables in startup folders, they can achieve arbitrary code execution with the privileges of the user. The vulnerability is addressed in versions V37.00, 36.01, 35.02, 34.04, 33.04, and 32.05.

Affected products

  • Rockwell Automation Studio 5000 Logix Designer V36.00, 35.00, 35.01, 34.00-34.03, 33.00-33.03, 32.00-32.04 and older

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: patched

References

Related threats