AllCyberNews

CVE-2026-9127

Studio 5000 Logix Designer® – Multiple Vulnerabilities

CVSS 7.3 high · Rockwell Automation Studio 5000 Logix Designer · published 2026-07-14

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

Coverage 1 source

  1. 2026-07-21 CISA Cybersecurity Advisories high Rockwell Automation Studio 5000 Logix Designer

    Rockwell Automation Studio 5000 Logix Designer has multiple vulnerabilities allowing local attackers to execute arbitrary files or code.

Mentioned with

CVE-2026-9108 CVE-2026-9128

Also covered