CVE-2026-9128 Details
Description
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.
A code execution vulnerability exists in Rockwell Automation's Studio 5000 Logix Designer due to an unquoted search path in the External Tools configuration. The vulnerability affects versions 35.00, 34.00-34.02, 33.00-33.02, 32.00-32.04 and older. The issue arises because executable paths in the external tools configuration file are not properly quoted, allowing the operating system to misinterpret them and execute unintended files. This flaw could be exploited by placing a malicious executable in a location within the search path, leading to arbitrary code execution with the same user permissions as the person running the application.
Users can upgrade to version 36.00, 35.01, 34.03, 33.03 or 32.05 to address this vulnerability. For those unable to upgrade, Rockwell Automation recommends following their security best practices.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1783.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rockwellautomation studio 5000 logix designer | < 32.05 >= 33.00, < 33.03 >= 34.00, < 34.03 35.00 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | Initial Analysis | [email protected] |
| Jul 14, 2026 | New CVE Received | [email protected] |
| Jul 14, 2026 | CVE Modified | CISA-ADP |