
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-44468 is a local privilege escalation vulnerability in CODESYS Development System caused by incorrect default permissions (CWE-276) set on a directory created during administrative installation. A low-privileged local attacker can modify a temporary file that defines which components are installed, forcing the deployment of arbitrary components and escalating privileges. The vulnerability affects CODESYS Development System versions prior to 3.5.22.20 (including from 3.0.0.0). It was published on May 26, 2026, with a CVSS v3.1 score of 7.8 (High) and a CVSS v4.0 score of 8.5 (High) (GitHub Advisory, CERTVDE).
The root cause is CWE-276 (Incorrect Default Permissions): during administrative installation, CODESYS Development System creates a directory with overly permissive access controls, allowing low-privileged users to read and write its contents. A temporary file within this directory specifies the components to be installed; by modifying this file before or during the installation process, an attacker can inject arbitrary components that will be deployed with elevated (administrative) privileges. The attack vector is local, requires low privileges, no user interaction, and low attack complexity, making it straightforward to exploit once local access is obtained (GitHub Advisory, CERTVDE).
Successful exploitation grants the attacker high impact across confidentiality, integrity, and availability of the vulnerable system, effectively achieving full local privilege escalation to administrative or SYSTEM-level access. An attacker who gains elevated privileges can install malicious software, access sensitive project files and credentials stored within the CODESYS development environment, tamper with PLC programs or configurations, and potentially pivot to connected operational technology (OT) networks. The subsequent system impact is rated None in CVSS v4.0, indicating the escalation is scoped to the local host, but the industrial context of CODESYS makes any privilege escalation particularly significant (GitHub Advisory, CERTVDE).
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.011% (1st percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
icacls or accesschk.exe to enumerate writable directories in the installation path or %TEMP%).msiexec.exe) with unusual child processes or command-line arguments; new services or scheduled tasks created during the installation window that are not part of the standard CODESYS component set.icacls or accesschk) that should normally be restricted to administrators.CODESYS has released version 3.5.22.20 of the CODESYS Development System, which addresses this vulnerability by correcting the default permissions applied to the directory created during administrative installation (CERTVDE, GitHub Advisory). Organizations should upgrade to version 3.5.22.20 or later as the primary remediation. As a workaround prior to patching, administrators should restrict access to the CODESYS installation directories and temporary folders using OS-level ACLs, and ensure that administrative installations are performed only in controlled environments where low-privileged users cannot access the file system during the installation process.
The vulnerability was assigned and disclosed by CERTVDE (VDE-2026-055) and published to the GitHub Advisory Database on May 26, 2026. No notable public researcher commentary, social media discussion, or significant media coverage beyond standard vulnerability aggregator postings has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."