Security & Threat Intelligence · 13.08.2026, 16:55 UTC
Siemens License Server (SLS)
| Schweregrad | info |
|---|---|
| CVE | ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 13.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-69108, CVE-2026-69109. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version. The following versions of Siemens License Server (SLS) are affected:
Siemens License Server (SLS) vers:intdot/<5.1, vers:intdot/<5.3 (CVE-2026-69108, CVE-2026-69109)
CVSS Vendor Equipment Vulnerabilities
v3 7.5 Siemens Siemens License Server (SLS) Incorrect Permission Assignment for Critical Resource, Path Traversal: '.../...//'
Background
Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-69108
The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise. View CVE Details
Affected Products Siemens License Server (SLS)
Vendor:Siemens Product Version:Siemens License Server (SLS) < V5.1 Product Status:known_affected
Remediations Vendor fixUpdate to V5.1 or later versionhttps://support.sw.siemens.com/product/1586485382/
Relevant CWE: CWE-732 Incorrect Permission Assignment for Critical Resource
Metrics
CVSS Version Base Score Base Severity Vector String
3.1 6 MEDIUM CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CVE-2026-69109
The affected application is vulnerable to a path traversal …