Security Flaw in ControlFLASH™ Installation by Rockwell Automation
CVE-2026-12663

7HIGH

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-12663?

A critical security flaw in ControlFLASH™ arises from the installer mistakenly granting write permissions to the 'Everyone' group on the product installation directory. This misconfiguration can lead to arbitrary code execution, enabling attackers to potentially execute any commands or code with the same privileges as the logged-in user, thereby compromising system integrity and security.

Affected Version(s)

ControlFLASH ® V15.07 and prior

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.