As cited
Copy frozen at (site build).
vulnerabilities
Siemens License Server (SLS)
Siemens License Server (SLS) versions prior to 5.1 and 5.3 contain two vulnerabilities: CVE-2026-69108, a local privilege escalation flaw with a CVSS score of 6.0 (Medium) that stems from insecure sudoers policy configuration, and CVE-2026-69109, a path traversal vulnerability with a CVSS score of 7.5 (High) that allows remote file access. Siemens has released patched versions and recommends immediate updates to mitigate the risks of arbitrary command execution and unauthorized file disclosure.
Why it matters: Organizations deploying Siemens License Server in critical infrastructure or IT environments must patch to version 5.1 or later (for CVE-2026-69108) and version 5.3 or later (for CVE-2026-69109) to prevent privilege escalation and remote file access attacks against unpatched instances.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Siemens License Server (SLS)
Siemens License Server (SLS) versions prior to 5.1 and 5.3 contain two vulnerabilities: CVE-2026-69108, a local privilege escalation flaw with a CVSS score of 6.0 (Medium) that stems from insecure sudoers policy configuration, and CVE-2026-69109, a path traversal vulnerability with a CVSS score of 7.5 (High) that allows remote file access. Siemens has released patched versions and recommends immediate updates to mitigate the risks of arbitrary command execution and unauthorized file disclosure.
Why it matters: Organizations deploying Siemens License Server in critical infrastructure or IT environments must patch to version 5.1 or later (for CVE-2026-69108) and version 5.3 or later (for CVE-2026-69109) to prevent privilege escalation and remote file access attacks against unpatched instances.
- Source published
- First seen by Cybersecurity Tracker