PT-2026-43196 · Codesys · Codesys Development System

David Ruscheweyh

·

Published

2026-05-26

·

Updated

2026-05-26

·

CVE-2026-44468

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2026-44468

Affected Products

Codesys Development System