CVE-2026-9127 Details
Description
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.
A remote code execution vulnerability has been identified in Rockwell Automation's Studio 5000 Logix Designer, affecting versions 35.00, 34.00, 34.01, 33.00, 33.02, 32.00-32.04 and older. The issue arises from incorrect authorization on a configuration file, allowing any authenticated user to modify the paths of external tools within the application. Exploitation of this vulnerability could enable an attacker to redirect these paths to a malicious executable, leading to arbitrary code execution when users engage with the external tools feature.
Users can upgrade to Studio 5000 Logix Designer versions 36.00, 35.01, 34.02, 33.02 or 32.05 to address this vulnerability. For those unable to upgrade, Rockwell Automation recommends following their security best practices.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1783.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rockwellautomation studio 5000 logix designer | <= 32.04 >= 33.00, < 33.02 >= 34.00, < 34.02 35.00 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | Initial Analysis | [email protected] |
| Jul 14, 2026 | New CVE Received | [email protected] |
| Jul 14, 2026 | CVE Modified | CISA-ADP |