CVE-2026-44468: Incorrect Default Permissions in CODESYS Development System
The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Ensure the temporary directory created during the CODESYS Development System administrative installation has restrictive permissions so a low-privileged local user cannot modify the temporary file that defines the components to be installed.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44468?
The severity of CVE-2026-44468 is rated as high, with a score of 7.8.
How do I fix CVE-2026-44468?
To fix CVE-2026-44468, ensure that the permissions for directories created during the administrative installation are set securely.
What impact does CVE-2026-44468 have on security?
CVE-2026-44468 allows low-privileged local attackers to escalate privileges, potentially compromising the system.
Who is affected by CVE-2026-44468?
CVE-2026-44468 affects users of the CODESYS Development System who perform administrative installations.
Can CVE-2026-44468 be exploited remotely?
CVE-2026-44468 cannot be exploited remotely, as it requires local access to the system.