Security Flaw in ControlFLASH™ Installation by Rockwell Automation
CVE-2026-12663
7HIGH
What is CVE-2026-12663?
A critical security flaw in ControlFLASH™ arises from the installer mistakenly granting write permissions to the 'Everyone' group on the product installation directory. This misconfiguration can lead to arbitrary code execution, enabling attackers to potentially execute any commands or code with the same privileges as the logged-in user, thereby compromising system integrity and security.
Affected Version(s)
ControlFLASH ® V15.07 and prior