CVE-2026-9127: Studio 5000 Logix Designer® – Multiple Vulnerabilities
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9127?
The severity of CVE-2026-9127 is rated high with a score of 7.3 on the CVSS scale.
What are the potential impacts of CVE-2026-9127?
CVE-2026-9127 can lead to remote code execution, allowing attackers to modify application configurations.
Who is affected by CVE-2026-9127?
Any user of Rockwell Automation's Studio 5000 Logix Designer could be affected if they have authenticated access.
How do I fix CVE-2026-9127?
To mitigate CVE-2026-9127, ensure that proper authorization controls are implemented for configuration files.
When was CVE-2026-9127 published?
CVE-2026-9127 was published on July 14, 2026.