Description
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.
Published: 2026-07-14
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote code execution vulnerability exists in Studio 5000 Logix Designer due to missing authorization checks on a configuration file. It allows any authenticated user to modify the file that specifies paths to external tools. If an attacker changes these paths to point to a malicious executable, any user who interacts with the external tools functionality will cause the system to run the attacker’s code. The vulnerability is rooted in improper handling of authorization, corresponding to CWE-863.

Affected Systems

The affected product is Rockwell Automation's Studio 5000 Logix Designer. The issue is present for any user who can authenticate to the application and manipulate the configuration file that controls external tool paths. No specific version information is provided, so all releases of the product may be at risk until patched.

Risk and Exploitability

The assigned CVSS score of 7.3 classifies the vulnerability as high severity. The EPSS score is below 1 percent, indicating a low probability of widespread exploitation, and it is not currently listed in the CISA KEV catalog. The attack requires authenticated access; therefore it is most likely to be leveraged in environments where users have sufficient privileges or where credentials can be obtained. Once exploited, the vulnerability would allow arbitrary code execution with the privileges of the affected user, potentially compromising system integrity and confidentiality.

Generated by OpenCVE AI on July 31, 2026 at 10:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the official Rockwell Automation advisory for Studio 5000 Logix Designer at https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1783.html and apply any vendor-provided fix or update that resolves the authorization issue.
  • Restrict permissions so that only authorized administrators can edit the configuration file that defines external tool paths.
  • Enable audit logging for changes to the configuration file and review logs regularly for any unauthorized modifications.

Generated by OpenCVE AI on July 31, 2026 at 10:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation studio 5000 Logix Designer
Vendors & Products Rockwellautomation
Rockwellautomation studio 5000 Logix Designer

Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.
Title Studio 5000 Logix Designer® – Multiple Vulnerabilities
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Rockwellautomation Studio 5000 Logix Designer
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-07-14T15:54:46.504Z

Reserved: 2026-05-20T17:48:19.830Z

Link: CVE-2026-9127

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:15:06Z

Weaknesses