Rockwell Automation Studio 5000 Logix Designer Vulnerabilities
Multiple security flaws were discovered in Rockwell Automation's Studio 5000 Logix Designer software. These issues could allow a local attacker to run unauthorized code or change program settings. Users are strongly advised to update their software to the latest versions provided by the vendor.

English Brief
Multiple security flaws were discovered in Rockwell Automation's Studio 5000 Logix Designer software. These issues could allow a local attacker to run unauthorized code or change program settings. Users are strongly advised to update their software to the latest versions provided by the vendor.
الموجز العربي
ثغرات أمنية في برنامج Rockwell Automation Studio 5000 Logix Designer
تم اكتشاف ثغرات أمنية متعددة في برنامج Rockwell Automation Studio 5000 Logix Designer. قد تسمح هذه الثغرات لمهاجم محلي بتشغيل برمجيات غير مصرح بها أو تغيير إعدادات البرنامج. يُنصح المستخدمون بشدة بتحديث البرنامج إلى أحدث الإصدارات التي توفرها الشركة المصنعة.
- 1Identify current version of Rockwell Automation Studio 5000 Logix Designer
- 2Compare installed version against patched versions: V37.00, 36.01, 35.02, 34.04, 33.04, 32.05
- 3Download updates from the official Rockwell Automation Support portal
English Advisory
// Intelligence Summary
Rockwell Automation has addressed three vulnerabilities in Studio 5000 Logix Designer (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) that could result in arbitrary code execution or unauthorized configuration modification. These flaws affect multiple versions of the software.
التقرير العربي
// ملخص استخباراتي
عالجت شركة Rockwell Automation ثلاث ثغرات أمنية في برنامج Studio 5000 Logix Designer (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) قد تؤدي إلى تنفيذ تعليمات برمجية عشوائية أو تعديل غير مصرح به للإعدادات. تؤثر هذه الثغرات على إصدارات متعددة من البرنامج.
// Technical Context
CVE-2026-9108 is a Path Traversal vulnerability arising from improper sanitization of file paths within .ACD project files, enabling arbitrary file writes. CVE-2026-9127 involves improper authorization on configuration files, allowing authenticated users to redirect external tool paths to malicious binaries. CVE-2026-9128 is an Unquoted Search Path vulnerability, where unquoted executable paths with spaces permit execution hijacking via malicious binaries placed in the search path.
// السياق الفني
تُعد ثغرة CVE-2026-9108 ثغرة اجتياز مسار (Path Traversal) ناتجة عن عدم التحقق من صحة مسارات الملفات داخل مشاريع .ACD، مما يتيح كتابة ملفات عشوائية. تتضمن ثغرة CVE-2026-9127 تفويضاً غير صحيح في ملفات التكوين، مما يسمح للمستخدمين المصادق عليهم بإعادة توجيه مسارات الأدوات الخارجية إلى ملفات تنفيذية ضارة. أما ثغرة CVE-2026-9128 فهي ثغرة مسار بحث غير مقتبس (Unquoted Search Path)، حيث تسمح المسارات التي تحتوي على مسافات باختطاف التنفيذ عبر ملفات ضارة.
// Exposure Notes
Affected versions include various releases across V32, V33, V34, V35, and V36. Deployment of these versions within Critical Manufacturing environments remains a primary risk vector.
// ملاحظات التعرض
تشمل الإصدارات المتأثرة إصدارات مختلفة عبر V32 وV33 وV34 وV35 وV36. يظل استخدام هذه الإصدارات في بيئات التصنيع الحيوية ناقل خطر رئيسياً.
// Defensive Priority
Immediate transition to patched versions (e.g., V37.00, 36.01, 35.02, 34.04, 33.04, 32.05) is the primary mitigation. In the absence of patching, adhere to Rockwell Automation's established security best practices for hardening industrial control workstations.
// أولوية الدفاع
يعد الانتقال الفوري إلى الإصدارات المصححة (مثل V37.00، 36.01، 35.02، 34.04، 33.04، 32.05) هو خط الدفاع الأساسي. في حالة عدم التمكن من التحديث، يجب الالتزام بأفضل الممارسات الأمنية التي حددتها Rockwell Automation لتأمين محطات عمل التحكم الصناعي.
Mitigation Checklist
- 1Identify current version of Rockwell Automation Studio 5000 Logix Designer
- 2Compare installed version against patched versions: V37.00, 36.01, 35.02, 34.04, 33.04, 32.05
- 3Download updates from the official Rockwell Automation Support portal
- 4Perform off-line testing before deploying in production environments
- 5Apply the vendor-provided security best practices as referenced in https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012
قائمة إجراءات التخفيف
- 1تحديد الإصدار الحالي من برنامج Rockwell Automation Studio 5000 Logix Designer
- 2مقارنة الإصدار المثبت بالإصدارات المصححة: V37.00، 36.01، 35.02، 34.04، 33.04، 32.05
- 3تنزيل التحديثات من بوابة الدعم الرسمية لشركة Rockwell Automation
- 4إجراء اختبارات خارج نطاق العمل قبل النشر في بيئات الإنتاج
- 5تطبيق أفضل الممارسات الأمنية المقدمة من البائع كما هو موضح في https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012
- Source: CISA Alerts
# 1. Identify current version of Rockwell Automation Studio 5000 Logix Designer
# 2. Compare installed version against patched versions: V37.00, 36.01, 35.02, 34.04, 33.04, 32.05
# 3. Download updates from the official Rockwell Automation Support portal
# 4. Perform off-line testing before deploying in production environments
# 5. Apply the vendor-provided security best practices as referenced in https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012