Insecure Directory Permissions in Administrative Installation of Affected Product by Vendor
CVE-2026-44468

8.5HIGH

Key Information:

Vendor

Codesys

Vendor
CVE Published:
26 May 2026

What is CVE-2026-44468?

The affected product is vulnerable due to the creation of a directory with default permissions that are not securely configured during administrative installation. This flaw permits a local attacker with low privileges to manipulate a temporary file that specifies the components for installation. Consequently, the attacker can escalate their privileges by deploying arbitrary components, potentially compromising the system's integrity and security.

Affected Version(s)

CODESYS Development System 3.0.0.0 < 3.5.22.20

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

David Ruscheweyh from SEW-EURODRIVE GmbH & Co KG
.