Junglewise Threat Intelligence

CVE-2026-9127: Rockwell Automation Studio 5000 Logix Designer incorrect authorization in configuration file

CVE-2026-9127 · Severity: info · CVSS 7.3 · Published 2026-07-14

Technologies: Rockwell Automation Studio 5000 Logix Designer. Vendors: Rockwell Automation.

Executive brief

Studio 5000 Logix Designer, a software suite used to program industrial automation controllers, contains a security flaw in how it manages its configuration files. An authorized user on the system can modify the paths used to launch external tools, redirecting them to run malicious software instead. If another user then attempts to use those tools, the attacker's malicious code will execute, potentially leading to a full system compromise or disruption of industrial operations.

Technical details

A vulnerability classified as Incorrect Authorization (CWE-863) exists in Rockwell Automation Studio 5000 Logix Designer. The application fails to properly restrict access to a configuration file that defines the execution paths for external tools. An authenticated local attacker can modify these paths to point to a malicious executable. Arbitrary code execution occurs when a victim subsequently interacts with the 'external tools' functionality within the application. The attack requires local access and user interaction, but results in high impact to confidentiality, integrity, and availability. Patches are available in versions V36.00, 35.01, 34.02, 33.02, and 32.05.

Affected products

  • Rockwell Automation Studio 5000 Logix Designer V35.00, 34.00, 34.01, 33.00, 33.02, 32.00-32.04 and older

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory
  • 2026-07-14: patched

References

Related threats