CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Siemens License Server (SLS)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4388

As cited

Copy frozen at (site build).

vulnerabilities

Siemens License Server (SLS)

Siemens License Server (SLS) versions prior to 5.1 and 5.3 contain two vulnerabilities: CVE-2026-69108, a local privilege escalation flaw with a CVSS score of 6.0 (Medium) that stems from insecure sudoers policy configuration, and CVE-2026-69109, a path traversal vulnerability with a CVSS score of 7.5 (High) that allows remote file access. Siemens has released patched versions and recommends immediate updates to mitigate the risks of arbitrary command execution and unauthorized file disclosure.

Why it matters: Organizations deploying Siemens License Server in critical infrastructure or IT environments must patch to version 5.1 or later (for CVE-2026-69108) and version 5.3 or later (for CVE-2026-69109) to prevent privilege escalation and remote file access attacks against unpatched instances.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Siemens License Server (SLS)

Siemens License Server (SLS) versions prior to 5.1 and 5.3 contain two vulnerabilities: CVE-2026-69108, a local privilege escalation flaw with a CVSS score of 6.0 (Medium) that stems from insecure sudoers policy configuration, and CVE-2026-69109, a path traversal vulnerability with a CVSS score of 7.5 (High) that allows remote file access. Siemens has released patched versions and recommends immediate updates to mitigate the risks of arbitrary command execution and unauthorized file disclosure.

Why it matters: Organizations deploying Siemens License Server in critical infrastructure or IT environments must patch to version 5.1 or later (for CVE-2026-69108) and version 5.3 or later (for CVE-2026-69109) to prevent privilege escalation and remote file access attacks against unpatched instances.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary