CVE-2026-9128: Studio 5000 Logix Designer® – Multiple Vulnerabilities
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update the External Tools configuration so that every executable path specified is properly quoted. This prevents the OS from resolving paths containing spaces to unintended executables earlier in the search order.
Studio 5000 Logix Designer (External Tools configuration) Executable paths in the external tools configuration file = Quote all executable paths (wrap each path containing spaces in quotes)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9128?
The severity of CVE-2026-9128 is high with a CVSS score of 7.3.
How do I fix CVE-2026-9128?
To fix CVE-2026-9128, ensure that the executable paths in the External Tools configuration are properly quoted to address the unquoted search path issue.
What are the potential risks associated with CVE-2026-9128?
The potential risks of CVE-2026-9128 include unauthorized code execution due to improper handling of executable paths.
Which software is affected by CVE-2026-9128?
CVE-2026-9128 affects Rockwell Automation Studio 5000 Logix Designer.
When was CVE-2026-9128 published?
CVE-2026-9128 was published on July 14, 2026.