CVE-2026-44468
CODESYS Development System vulnerability analysis and mitigation

Overview

CVE-2026-44468 is a local privilege escalation vulnerability in CODESYS Development System caused by incorrect default permissions (CWE-276) set on a directory created during administrative installation. A low-privileged local attacker can modify a temporary file that defines which components are installed, forcing the deployment of arbitrary components and escalating privileges. The vulnerability affects CODESYS Development System versions prior to 3.5.22.20 (including from 3.0.0.0). It was published on May 26, 2026, with a CVSS v3.1 score of 7.8 (High) and a CVSS v4.0 score of 8.5 (High) (GitHub Advisory, CERTVDE).

Technical details

The root cause is CWE-276 (Incorrect Default Permissions): during administrative installation, CODESYS Development System creates a directory with overly permissive access controls, allowing low-privileged users to read and write its contents. A temporary file within this directory specifies the components to be installed; by modifying this file before or during the installation process, an attacker can inject arbitrary components that will be deployed with elevated (administrative) privileges. The attack vector is local, requires low privileges, no user interaction, and low attack complexity, making it straightforward to exploit once local access is obtained (GitHub Advisory, CERTVDE).

Impact

Successful exploitation grants the attacker high impact across confidentiality, integrity, and availability of the vulnerable system, effectively achieving full local privilege escalation to administrative or SYSTEM-level access. An attacker who gains elevated privileges can install malicious software, access sensitive project files and credentials stored within the CODESYS development environment, tamper with PLC programs or configurations, and potentially pivot to connected operational technology (OT) networks. The subsequent system impact is rated None in CVSS v4.0, indicating the escalation is scoped to the local host, but the industrial context of CODESYS makes any privilege escalation particularly significant (GitHub Advisory, CERTVDE).

Exploitability

As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.011% (1st percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Gain local access: Obtain a low-privileged local user account on a Windows system where CODESYS Development System (version < 3.5.22.20) is installed or is being installed by an administrator.
  2. Identify the insecure directory: Locate the temporary directory created during administrative installation of CODESYS Development System, which is created with world-writable or otherwise overly permissive default permissions (e.g., using icacls or accesschk.exe to enumerate writable directories in the installation path or %TEMP%).
  3. Monitor for installation activity: Wait for or trigger an administrative installation or update of CODESYS Development System, which creates the vulnerable temporary directory and component definition file.
  4. Modify the temporary component file: Write or overwrite the temporary file that defines the components to be installed, replacing legitimate component references with paths to attacker-controlled malicious binaries or scripts.
  5. Force deployment of arbitrary components: Allow the installation process to continue; the installer reads the modified file and deploys the attacker-specified components with administrative privileges, resulting in code execution at an elevated privilege level (GitHub Advisory, CERTVDE).

Indicators of compromise

  • File System: Unexpected or recently modified files in the CODESYS installation temporary directory during or after an administrative installation; presence of unknown binaries or scripts in CODESYS component directories; file timestamps inconsistent with legitimate installation activity.
  • Logs: Windows Event Logs (Security/Application) showing installation of unexpected components or services during a CODESYS administrative install session; entries from Windows Installer (MsiInstaller) referencing unusual file paths or component GUIDs.
  • Process: Unexpected processes spawned by the CODESYS installer (e.g., msiexec.exe) with unusual child processes or command-line arguments; new services or scheduled tasks created during the installation window that are not part of the standard CODESYS component set.
  • File System Permissions: Directories under the CODESYS installation or temp path with world-writable ACLs (detectable via icacls or accesschk) that should normally be restricted to administrators.

Mitigation and workarounds

CODESYS has released version 3.5.22.20 of the CODESYS Development System, which addresses this vulnerability by correcting the default permissions applied to the directory created during administrative installation (CERTVDE, GitHub Advisory). Organizations should upgrade to version 3.5.22.20 or later as the primary remediation. As a workaround prior to patching, administrators should restrict access to the CODESYS installation directories and temporary folders using OS-level ACLs, and ensure that administrative installations are performed only in controlled environments where low-privileged users cannot access the file system during the installation process.

Community reactions

The vulnerability was assigned and disclosed by CERTVDE (VDE-2026-055) and published to the GitHub Advisory Database on May 26, 2026. No notable public researcher commentary, social media discussion, or significant media coverage beyond standard vulnerability aggregator postings has been identified at this time.

Additional resources


SourceThis report was generated using AI

Related CODESYS Development System vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44469HIGH8.5
  • CODESYS Development System logoCODESYS Development System
  • cpe:2.3:a:codesys:development_system
NoYesMay 26, 2026
CVE-2026-44468HIGH8.5
  • CODESYS Development System logoCODESYS Development System
  • cpe:2.3:a:codesys:development_system
NoYesMay 26, 2026
CVE-2025-41700HIGH7.8
  • CODESYS Development System logoCODESYS Development System
  • cpe:2.3:a:codesys:development_system
NoYesDec 01, 2025
CVE-2023-5751HIGH7.8
  • CODESYS Development System logoCODESYS Development System
  • cpe:2.3:a:codesys:development_system
NoYesJun 04, 2024
CVE-2023-49675HIGH7.8
  • CODESYS Development System logoCODESYS Development System
  • cpe:2.3:a:codesys:development_system
NoNoMay 06, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management