Description
A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.
Published: 2026-09-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

A vulnerability in Rockwell Automation Arena allows a remote attacker to execute arbitrary code when the application parses a malicious DOE file or loads a page that forces the parser to handle such a file. The flaw is an out-of-bounds write that writes past the end of an allocated object, permitting an attacker to place and run code in the context of the current Arena process. This results in a loss of confidentiality and integrity critical to the system and can be leveraged by a user who opens a malicious file or visits a malicious page.

Affected Systems

All versions of Rockwell Automation Arena up to and including 16.20.08 are affected. The issue is present in all affected releases regardless of configuration as the vulnerability is triggered during the parsing of DOE files.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate to high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited or no current exploitation. The vulnerability can be triggered by a legitimate user who opens a malicious DOE file or visits a malicious web page, meaning the attack depends on user interaction or social engineering. The exploitation path involves delivering or hosting a malicious DOE file that triggers the out-of-bounds write, after which the attacker can execute code with the privileges of the Arena process.

Generated by OpenCVE AI on September 3, 2026 at 16:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the current version of Arena; if it is 16.20.08 or earlier, keep it isolated or plan for a future upgrade pending an official vendor fix.
  • Restrict or disable processing of DOE files from untrusted sources. If the file‑parsing feature is not essential to operations, consider removing or disabling it until a vendor patch is available.
  • Apply application sandboxing or isolation measures so that even if the vulnerability is exploited, the attacker’s impact is contained to the sandboxed process.
  • Use network or content filtering to block malicious web pages that could drive the Arena application into processing a vulnerable DOE file.

Generated by OpenCVE AI on September 3, 2026 at 16:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation arena
Vendors & Products Rockwellautomation
Rockwellautomation arena

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.
Title Code Execution Vulnerability in Arena®
First Time appeared Rockwell Automation
Rockwell Automation arena
CPEs cpe:2.3:a:rockwell_automation:arena:all_versions_16.20.08_and_prior:*:*:*:*:*:*:*
Vendors & Products Rockwell Automation
Rockwell Automation arena
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rockwell Automation Arena
Rockwellautomation Arena
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-09-03T13:33:55.331Z

Reserved: 2026-04-10T13:59:17.867Z

Link: CVE-2026-6071

cve-icon Vulnrichment

Updated: 2026-09-03T13:33:49.851Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-03T14:17:00.540

Modified: 2026-09-03T18:12:56.407

Link: CVE-2026-6071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T17:00:06Z

Weaknesses