CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Rockwell Automation ControlFLASH

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5655

As cited

Copy frozen at (site build).

vulnerabilities

Rockwell Automation ControlFLASH

Rockwell Automation ControlFLASH versions 15.07 and earlier contain CVE-2026-12663, a missing authentication vulnerability where the installer grants write permissions to the Everyone group on the installation directory. This allows arbitrary code execution at the permission level of the logged-in user. The vendor released version 15.08 with a fix and provided mitigation steps to remove the Everyone group permissions from the installation folder.

Why it matters: Organizations running ControlFLASH in critical manufacturing, energy, water, and wastewater environments must upgrade to version 15.08 or apply the documented permission removal steps immediately to prevent local code execution by low-privileged attackers.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Rockwell Automation ControlFLASH

Rockwell Automation ControlFLASH versions 15.07 and earlier contain CVE-2026-12663, a missing authentication vulnerability where the installer grants write permissions to the Everyone group on the installation directory. This allows arbitrary code execution at the permission level of the logged-in user. The vendor released version 15.08 with a fix and provided mitigation steps to remove the Everyone group permissions from the installation folder.

Why it matters: Organizations running ControlFLASH in critical manufacturing, energy, water, and wastewater environments must upgrade to version 15.08 or apply the documented permission removal steps immediately to prevent local code execution by low-privileged attackers.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary