SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-9128

HIGH · CVSS 7.3 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Studio 5000 Logix Designer® is vulnerable due to an unquoted search path in its External Tools configuration, which can lead to arbitrary code execution if an attacker places a malicious executable in the search path. This flaw allows the attacker to execute code with the same permissions as the user running the application, potentially compromising system integrity. Organizations using this software should prioritize remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-9128
Severity
HIGH
CVSS
7.3
EPSS
0.10%

Original NVD Description

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.