LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-9127

rockwellautomation · studio 5000 logix designer

Published
CVSS7.5
Severityhigh
WeaknessCWE-863
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Description

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-9127

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-9127.