Security & Threat Intelligence · 23.07.2026, 18:07 UTC
Rockwell Automation ThinManager
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA ICS Advisories · CISA Advisories ↗ |
| Veröffentlicht | 23.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-11917. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The following versions of Rockwell Automation ThinManager are affected:
ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2
CVSS Vendor Equipment Vulnerabilities
v3 8.1 Rockwell Automation Rockwell Automation ThinManager Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Background
Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-11917
A path traversal security issue exists within Rockwell Automation ThinManager software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory. View CVE Details
Affected Products Rockwell Automation ThinManager
Vendor:Rockwell Automation Product Version:Rockwell Automation ThinManager: >=13.0.0|<13.0.7, Rockwell Automation ThinManager: >=13.1.0|<13.1.5, Rockwell Automation ThinManager: >=13.2.0|<13.2.4, Rockwell Automation ThinManager: >=14.0.0|<14.0.2 Product Status:known_affected
Remediations MitigationUsers using the affected software, should upgrade to one of the corrected versions as follows: Vendor …