The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-055/ |
|
History
Tue, 26 May 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components. | |
| Title | Incorrect Default Permissions in CODESYS Development System | |
| First Time appeared |
Codesys
Codesys codesys Development System |
|
| Weaknesses | CWE-276 | |
| CPEs | cpe:2.3:a:codesys:codesys_development_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Codesys
Codesys codesys Development System |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-05-26T06:37:53.259Z
Reserved: 2026-05-06T17:08:03.356Z
Link: CVE-2026-44468
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses