OS Command Injection in Universal Robots PolyScope Dashboard Server
CVE-2026-8153

9.8CRITICAL

Key Information:

Vendor
CVE Published:
8 May 2026

Badges

๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

What is CVE-2026-8153?

The OS command injection vulnerability in the Dashboard Server interface of Universal Robots' PolyScope allows unauthorized users to execute arbitrary commands on the operating system of the robot. This can lead to potential manipulation or control of the robotic system, compromising its security and operational integrity. It is critical for users to ensure their versions are updated to 5.21.1 or later to mitigate this risk.

Affected Version(s)

PolyScope 5 0 < 5.25.1

News Articles

Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control

An attacker can exploit the command injection flaw to gain remote access to robotic systems, causing significant disruption to the environment.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by Dark Reading

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vera Mens of Claroty Team82
.