Description
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.
Published: 2026-08-11
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local privilege escalation vulnerability exists in Siemens License Server (SLS) versions older than V5.1. The flaw arises from an insecure sudoers policy that permits authenticated local users to execute commands with elevated privileges. An attacker who can gain local access to the system can run arbitrary commands as root and deploy malicious files, resulting in complete system compromise. This weakness is mapped to CWE‑732, which enumerates insecure or missing permissions for users.

Affected Systems

The vulnerability affects all Siemens License Server (SLS) deployments with versions earlier than V5.1. No specific vendor version penalty beyond the general < V5.1 threshold is noted.

Risk and Exploitability

The CVSS score of 8.3 classifies the flaw as high severity. Because the attack requires local access and relies on an insecure sudoers configuration, the likelihood of exploitation depends on the level of local user access, which may vary across environments. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the high CVSS value warrants immediate remediation.

Generated by OpenCVE AI on August 12, 2026 at 00:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Siemens' product portal for an available update that addresses the insecure sudoers policy, and apply the patch once available.
  • Verify and correct the sudoers configuration to remove unwarranted root privileges for local users, restricting allowed commands to only those explicitly required.
  • Enforce least privilege on all SLS user accounts and restrict local physical and network access to critical servers to reduce attack surface.

Generated by OpenCVE AI on August 12, 2026 at 00:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens siemens License Server (sls)
Vendors & Products Siemens
Siemens siemens License Server (sls)

Wed, 12 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Insecure Sudoers Policy in Siemens License Server

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Siemens License Server (sls)
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-11T14:47:32.332Z

Reserved: 2026-08-03T13:10:24.060Z

Link: CVE-2026-69108

cve-icon Vulnrichment

Updated: 2026-08-11T14:47:27.013Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T13:19:01.883

Modified: 2026-08-28T19:03:37.837

Link: CVE-2026-69108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:54:24Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource