Insecure Directory Permissions in Administrative Installation of Affected Product by Vendor
CVE-2026-44468
8.5HIGH
What is CVE-2026-44468?
The affected product is vulnerable due to the creation of a directory with default permissions that are not securely configured during administrative installation. This flaw permits a local attacker with low privileges to manipulate a temporary file that specifies the components for installation. Consequently, the attacker can escalate their privileges by deploying arbitrary components, potentially compromising the system's integrity and security.
Affected Version(s)
CODESYS Development System 3.0.0.0 < 3.5.22.20
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
David Ruscheweyh from SEW-EURODRIVE GmbH & Co KG
