As cited
Copy frozen at (site build).
vulnerabilities
Rockwell Automation ControlFLASH
Rockwell Automation ControlFLASH versions 15.07 and earlier contain CVE-2026-12663, a missing authentication vulnerability where the installer grants write permissions to the Everyone group on the installation directory. This allows arbitrary code execution at the permission level of the logged-in user. The vendor released version 15.08 with a fix and provided mitigation steps to remove the Everyone group permissions from the installation folder.
Why it matters: Organizations running ControlFLASH in critical manufacturing, energy, water, and wastewater environments must upgrade to version 15.08 or apply the documented permission removal steps immediately to prevent local code execution by low-privileged attackers.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Rockwell Automation ControlFLASH
Rockwell Automation ControlFLASH versions 15.07 and earlier contain CVE-2026-12663, a missing authentication vulnerability where the installer grants write permissions to the Everyone group on the installation directory. This allows arbitrary code execution at the permission level of the logged-in user. The vendor released version 15.08 with a fix and provided mitigation steps to remove the Everyone group permissions from the installation folder.
Why it matters: Organizations running ControlFLASH in critical manufacturing, energy, water, and wastewater environments must upgrade to version 15.08 or apply the documented permission removal steps immediately to prevent local code execution by low-privileged attackers.
- Source published
- First seen by Cybersecurity Tracker