CVE-2026-9108: Studio 5000 Logix Designer® – Multiple Vulnerabilities
A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9108?
CVE-2026-9108 has a medium severity with a CVSS score of 5.4.
What type of vulnerability is identified in CVE-2026-9108?
CVE-2026-9108 is a path traversal vulnerability found in Studio 5000 Logix Designer®.
How does CVE-2026-9108 affect Studio 5000 Logix Designer®?
CVE-2026-9108 allows attackers to exploit improper limitation of file paths within ACD project files.
How can I mitigate the risks associated with CVE-2026-9108?
To mitigate CVE-2026-9108, ensure that file names within ACD project files are properly sanitized and validated.
When was CVE-2026-9108 published?
CVE-2026-9108 was published on July 14, 2026.