CVE-2026-11917: ThinManager® - Path Traversal via API
A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11917?
CVE-2026-11917 has a high severity rating of 7.2.
How do I fix CVE-2026-11917?
To mitigate CVE-2026-11917, ensure that you apply the latest security patches provided by Rockwell Automation for ThinManager®.
What types of attacks can exploit CVE-2026-11917?
CVE-2026-11917 can be exploited by authenticated attackers to write arbitrary files to restricted system directories.
What systems are affected by CVE-2026-11917?
CVE-2026-11917 affects the Rockwell Automation ThinManager® software.
How serious is the risk associated with CVE-2026-11917?
The risk level associated with CVE-2026-11917 is rated at 57, indicating a significant potential for impact.