CVE-2026-9128

EUVD-2026-43711
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.97%
Affected Products (NVD)
VendorProductVersion
rockwellautomationstudio_5000_logix_designer
𝑥
< 32.05
rockwellautomationstudio_5000_logix_designer
33.00 ≤
𝑥
< 33.03
rockwellautomationstudio_5000_logix_designer
34.00 ≤
𝑥
< 34.03
rockwellautomationstudio_5000_logix_designer
35.00
𝑥
= Vulnerable software versions