CVE-2026-9854: SYS600 RBAC mechanism vulnerability
Published Sep 3, 2026
·Updated
A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.
Affected Software
1 affected component
SYS600 RBAC mechanism
Event History
Sep 3, 2026
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
DescriptionWeakness
Frequently Asked Questions
1
Who is realistically exposed to this issue?
Organizations using the SYS600 RBAC mechanism are exposed where users have access to the engineering tools. Those users may be able to elevate privileges on the underlying Windows host.
2
What level of access does an attacker need?
The attacker needs access to the SYS600 engineering tools. The provided information does not indicate that unauthenticated or remote-only access is sufficient.
3
What could successful exploitation allow?
A user could elevate to administrator level on the underlying Windows host. This grants full control of that host machine.