Rockwell Automation ThinManager Path Traversal Vulnerability
A security flaw in Rockwell Automation ThinManager could allow an authenticated attacker to save malicious files into protected system areas, potentially damaging or altering system operations.

English Brief
A security flaw in Rockwell Automation ThinManager could allow an authenticated attacker to save malicious files into protected system areas, potentially damaging or altering system operations.
الموجز العربي
ثغرة تجاوز المسار في برنامج Rockwell Automation ThinManager
تم اكتشاف ثغرة أمنية في برنامج Rockwell Automation ThinManager قد تسمح لمهاجم لديه صلاحية وصول بحفظ ملفات ضارة في مناطق النظام المحمية، مما قد يؤدي إلى الإضرار بعمليات النظام أو تغييرها.
- 1Audit current version: Ensure you are running an affected version before proceeding.
- 2Download patches: Obtain the latest versions from the Rockwell Automation support portal.
- 3Apply updates:
English Advisory
// Intelligence Summary
Rockwell Automation has disclosed a path traversal vulnerability (CVE-2026-11917) affecting multiple versions of ThinManager. The vulnerability arises from improper input validation during file save operations within the API, allowing an authenticated attacker to write files outside of intended directories.
التقرير العربي
// ملخص المعلومات الاستخباراتية
أعلنت شركة Rockwell Automation عن وجود ثغرة تجاوز المسار (CVE-2026-11917) تؤثر على إصدارات متعددة من برنامج ThinManager. تنشأ الثغرة بسبب التحقق غير الكافي من المدخلات أثناء عمليات حفظ الملفات داخل واجهة برمجة التطبيقات (API)، مما يسمح لمهاجم مصرح له بكتابة ملفات خارج الأدلة المخصصة.
// Technical Context
Identified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), the flaw enables an authenticated remote attacker to bypass file system restrictions. Successful exploitation can lead to unauthorized modification of critical system configuration or binary files. The vulnerability carries a CVSS 3.1 base score of 8.1.
// السياق التقني
تم تحديد هذه الثغرة تحت التصنيف CWE-22 (الحد غير السليم لمسار الملف في دليل مقيد)، حيث تمكّن المهاجم المصرح له من تجاوز قيود نظام الملفات. يمكن أن يؤدي الاستغلال الناجح للثغرة إلى تعديل غير مصرح به لملفات تكوين النظام الحساسة. حصلت الثغرة على تقييم 8.1 وفق مقياس CVSS 3.1.
// Exposure Notes
Impacted products include: ThinManager 13.0.0 through 13.0.6, 13.1.0 through 13.1.4, 13.2.0 through 13.2.3, and 14.0.0 through 14.0.1. This issue primarily affects industrial environments in sectors such as Energy, Water and Wastewater, and Critical Manufacturing.
// ملاحظات التعرض
تشمل المنتجات المتأثرة إصدارات ThinManager من 13.0.0 إلى 13.0.6، ومن 13.1.0 إلى 13.1.4، ومن 13.2.0 إلى 13.2.3، ومن 14.0.0 إلى 14.0.1. تؤثر هذه المشكلة بشكل رئيسي على البيئات الصناعية في قطاعات مثل الطاقة والمياه والصرف الصحي والتصنيع الحساس.
// Defensive Priority
Users must update to the patched versions immediately: 13.0.8, 13.1.6, 13.2.5, or 14.0.3. If patching is not immediately feasible, restrict network access to ThinManager interfaces and implement robust egress/ingress filtering to isolate control systems from untrusted network segments. Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05
// الأولوية الدفاعية
يجب على المستخدمين الترقية إلى الإصدارات المصححة فوراً: 13.0.8 أو 13.1.6 أو 13.2.5 أو 14.0.3. إذا لم يكن التحديث ممكناً، يجب تقييد الوصول إلى واجهات ThinManager وتطبيق سياسات تصفية الشبكة لعزل أنظمة التحكم عن القطاعات غير الموثوقة. المصدر: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05
Mitigation Checklist
- 1Audit current version: Ensure you are running an affected version before proceeding.
- 2Download patches: Obtain the latest versions from the Rockwell Automation support portal.
- 3Apply updates:
- 4For 13.0.x, upgrade to 13.0.8
- 5For 13.1.x, upgrade to 13.1.6
- 6For 13.2.x, upgrade to 13.2.5
- 7For 14.0.x, upgrade to 14.0.3
- 8Network Isolation: Ensure ThinManager is not exposed to the public internet.
- 9Review Logs: Check application logs for unauthorized file write attempts.
قائمة إجراءات التخفيف
- 1تدقيق الإصدار الحالي: تأكد من تشغيل إصدار متأثر قبل المتابعة.
- 2تحميل التصحيحات: احصل على أحدث الإصدارات من بوابة دعم Rockwell Automation.
- 3تطبيق التحديثات:
- 4بالنسبة لإصدارات 13.0.x، قم بالترقية إلى 13.0.8
- 5بالنسبة لإصدارات 13.1.x، قم بالترقية إلى 13.1.6
- 6بالنسبة لإصدارات 13.2.x، قم بالترقية إلى 13.2.5
- 7بالنسبة لإصدارات 14.0.x، قم بالترقية إلى 14.0.3
- 8عزل الشبكة: تأكد من أن برنامج ThinManager غير مكشوف للإنترنت العام.
- 9مراجعة السجلات: افحص سجلات التطبيق بحثاً عن محاولات كتابة ملفات غير مصرح بها.
- Source: CISA Alerts
# Remediation Checklist for Rockwell Automation ThinManager
# 1. Audit current version: Ensure you are running an affected version before proceeding.
# 2. Download patches: Obtain the latest versions from the Rockwell Automation support portal.
# 3. Apply updates:
# - For 13.0.x, upgrade to 13.0.8
# - For 13.1.x, upgrade to 13.1.6
# - For 13.2.x, upgrade to 13.2.5
# - For 14.0.x, upgrade to 14.0.3
# 4. Network Isolation: Ensure ThinManager is not exposed to the public internet.
# 5. Review Logs: Check application logs for unauthorized file write attempts.