CVE-2026-44469: Incorrect Default Permissions in CODESYS Development System
The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting in local privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44469?
CVE-2026-44469 has a high severity rating of 7.8.
How do I fix CVE-2026-44469?
To fix CVE-2026-44469, ensure that proper file permissions are set during installation and avoid running the installation with low privilege levels.
What type of attack can exploit CVE-2026-44469?
CVE-2026-44469 can be exploited by a low-privileged local attacker using a TOCTOU race condition.
What is the main issue with CVE-2026-44469?
The main issue with CVE-2026-44469 is that it has incorrect default permissions for extracted installation files.
What software is affected by CVE-2026-44469?
CVE-2026-44469 affects the CODESYS Development System.