Description
A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.
Published: 2026-09-01
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

The vulnerability in ControlFLASH arises from improper access control, specifically the installer granting write permissions to the Everyone group on the product’s installation directory. This weakness enables an attacker to place malicious files in the directory, leading to arbitrary code execution. Once executed, the attacker would run any commands or code at the permission level of the logged‑in user.

Affected Systems

Rockwell Automation’s ControlFLASH product is affected, specifically all installations up to and including version 15.07 as indicated by the product identifier cpe:2.3:a:rockwell_automation:controlflash_:v15.07_and_prior:*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.

Risk and Exploitability

The CVSS score of 7 indicates a high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, so the overall risk is substantial but not known to be actively exploited. The likely attack vector is local: an attacker with local access or the ability to run the installer could exploit the excessive write permissions to enable code execution at the user’s privilege level.

Generated by OpenCVE AI on September 1, 2026 at 15:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Remove the Everyone group from the installation directory and set permissions to Owner only, thereby preventing unauthorized write access.
  • Apply any vendor‑supplied update or patch releasing after version 15.07 that corrects the installer’s permission handling.
  • Ensure that no shared or remote file systems allow write access to the ControlFLASH installation folder, especially for guest or service accounts.

Generated by OpenCVE AI on September 1, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation controlflash
Vendors & Products Rockwellautomation
Rockwellautomation controlflash

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.
Title ControlFLASH ® – Improper Access Control
First Time appeared Rockwell Automation
Rockwell Automation controlflash
Weaknesses CWE-306
CPEs cpe:2.3:a:rockwell_automation:controlflash_:v15.07_and_prior:*:*:*:*:*:*:*
Vendors & Products Rockwell Automation
Rockwell Automation controlflash
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rockwell Automation Controlflash
Rockwellautomation Controlflash
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-09-01T15:44:41.740Z

Reserved: 2026-06-18T19:02:36.861Z

Link: CVE-2026-12663

cve-icon Vulnrichment

Updated: 2026-09-01T15:44:38.878Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T14:17:24.290

Modified: 2026-09-01T20:50:01.960

Link: CVE-2026-12663

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:28:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function