OS Command Injection in Universal Robots PolyScope Dashboard Server
CVE-2026-8153
9.8CRITICAL
Key Information:
- Vendor
Universal Robots
- Status
- Vendor
- CVE Published:
- 8 May 2026
Badges
๐พ Exploit Exists๐ฐ News Worthy
What is CVE-2026-8153?
The OS command injection vulnerability in the Dashboard Server interface of Universal Robots' PolyScope allows unauthorized users to execute arbitrary commands on the operating system of the robot. This can lead to potential manipulation or control of the robotic system, compromising its security and operational integrity. It is critical for users to ensure their versions are updated to 5.21.1 or later to mitigate this risk.
Affected Version(s)
PolyScope 5 0 < 5.25.1
News Articles
Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control
An attacker can exploit the command injection flaw to gain remote access to robotic systems, causing significant disruption to the environment.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by Dark Reading
Vulnerability published
Vulnerability Reserved
Credit
Vera Mens of Claroty Team82
