Description
The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting in local privilege escalation.
Published: 2026-05-26
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when the CODESYS Development System extracts installation files into a temporary directory that is left with permissions that allow write access by lower‑privileged users. This incorrect default setting enables a low‑privileged local attacker to take advantage of a time‑of‑check-to-time‑of‑use race condition during administrative installation, replacing verified files with malicious ones before the installation process completes. The result is the attacker gaining elevated local privileges, a weakness identified as CWE‑276. The CVSS score of 8.5 marks the issue as high severity.

Affected Systems

CODESYS Development System by CODESYS is the affected product. No specific affected versions are listed in the available data, so all releases of this product may be vulnerable until a patch is released.

Risk and Exploitability

The high CVSS score indicates significant impact if exploited. The EPSS score is not supplied, so the likelihood of exploitation cannot be quantified, though the exploitation requires only local presence and a usable timing window for the race condition. KEV is not listable, meaning there are no confirmed public exploits in the CISA catalog. Consequently, the risk remains high for any environment where CODESYS Development System is installed under administrative privileges, especially if low‑privileged users have access to the installation directory during the installation process.

Generated by OpenCVE AI on May 26, 2026 at 08:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update CODESYS Development System to the latest version that corrects the default directory permissions.
  • Ensure the temporary installation directory is owned by an administrator and has permissions that prevent non‑administrator write access before the installation process begins.
  • If an update is unavailable, restrict or remove write permissions on the temporary directory manually and monitor for any unauthorized file changes during installation.

Generated by OpenCVE AI on May 26, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 28 May 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:*

Tue, 26 May 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 May 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Codesys development System
Vendors & Products Codesys development System

Tue, 26 May 2026 07:45:00 +0000

Type Values Removed Values Added
Description The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting in local privilege escalation.
Title Incorrect Default Permissions in CODESYS Development System
First Time appeared Codesys
Codesys codesys Development System
Weaknesses CWE-276
CPEs cpe:2.3:a:codesys:codesys_development_system:*:*:*:*:*:*:*:*
Vendors & Products Codesys
Codesys codesys Development System
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Codesys Codesys Development System Development System
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-05-26T10:48:51.345Z

Reserved: 2026-05-06T17:08:03.356Z

Link: CVE-2026-44469

cve-icon Vulnrichment

Updated: 2026-05-26T10:48:46.801Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-26T08:16:22.137

Modified: 2026-05-28T20:09:28.057

Link: CVE-2026-44469

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T08:30:46Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions