CVE-2026-9108 Details
Description
A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.
A path traversal vulnerability has been identified in Rockwell Automation's Studio 5000 Logix Designer, affecting versions 36.00, 35.00, 35.01, 34.00-34.03, 33.00-33.03, 32.00-32.04 and older. The issue arises from improper validation of file paths within ACD project files. When a project is opened, the software fails to sanitize file names embedded in the ACD file structure, allowing path traversal sequences to escape the intended extraction directory. Exploitation of this vulnerability could enable an attacker to create a malicious ACD project file that writes arbitrary files to locations controlled by the attacker on the file system, potentially leading to code execution.
Users can upgrade to version 37.00, 36.01, 35.02, 34.04, 33.04 or 32.05. For those unable to upgrade, Rockwell Automation recommends following their security best practices.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1783.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rockwellautomation studio 5000 logix designer | < 32.05 >= 33.00, < 33.04 >= 34.00, < 34.04 >= 35.00, < 35.02 36.00 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | Initial Analysis | [email protected] |
| Jul 14, 2026 | New CVE Received | [email protected] |
| Jul 14, 2026 | CVE Modified | CISA-ADP |