SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-9108

MEDIUM · CVSS 5.4 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Studio 5000 Logix Designer® is vulnerable to a path traversal issue that arises from inadequate validation of file paths in ACD project files. This flaw allows an attacker to manipulate file names within the project, potentially leading to arbitrary file writing and code execution on the affected system. Organizations using this software should prioritize addressing this vulnerability to mitigate risks associated with unauthorized file access and execution.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-9108
Severity
MEDIUM
CVSS
5.4
EPSS
0.11%

Original NVD Description

A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.