PT-2026-43197 · Codesys · Codesys Development System

·

CVE-2026-44469

·

Published

2026-05-26

·

Updated

2026-05-29

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CODESYS Development System (affected versions not specified)
Description The software extracts installation files to a temporary directory using incorrect default permissions during administrative installation. This allows a low-privileged local attacker to exploit a TOCTOU (Time-of-Check to Time-of-Use) race condition—a scenario where a system checks a condition and then uses the result, but the condition changes between the check and the use—to replace verified files with malicious ones before the installation completes, leading to local privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44469

Affected Products

Codesys Development System