CVE-2026-44469
CODESYS Development System vulnerability analysis and mitigation

Overview

CVE-2026-44469 is a local privilege escalation vulnerability in CODESYS Development System caused by incorrect default permissions on a temporary directory used during administrative installation. The affected product extracts installation files to a world-writable (or insufficiently restricted) temporary directory, enabling a TOCTOU (Time-of-Check to Time-of-Use) race condition that a low-privileged local attacker can exploit to replace verified files with malicious ones before they are installed. Affected versions span from 3.0.0.0 up to (but not including) 3.5.22.20. The vulnerability was published on May 26, 2026, with a CVSS v3.1 base score of 7.0 (High) and a CVSS v4.0 base score of 8.5 (High) (Github Advisory).

Technical details

The root cause is classified as CWE-276 (Incorrect Default Permissions): during administrative installation, CODESYS Development System extracts files to a temporary directory without applying restrictive access controls, leaving those files modifiable by low-privileged users (Github Advisory). The attack exploits a TOCTOU race condition — after the installer verifies the integrity of extracted files but before it copies them to their final destination, an attacker can swap the verified files with malicious payloads. The exploitation window is described as "practical," meaning it is large enough to be reliably exploited without requiring highly precise timing. The attack vector is local, requires low privileges, and no user interaction beyond the legitimate administrator initiating the installation process.

Impact

Successful exploitation results in local privilege escalation, granting the attacker high confidentiality, integrity, and availability impact on the vulnerable system. A low-privileged local user can elevate to the privilege level under which the installer runs (typically SYSTEM or administrator), enabling full control over the affected host. This could allow an attacker to install persistent malware, access sensitive engineering data within CODESYS projects, or pivot to connected industrial control systems and OT environments (Github Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation at the time of publication (Github Advisory). The EPSS score is approximately 0.011% (1st percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. While the exploitation window is described as practical, the local access requirement limits the attacker pool.

Exploitation steps

  1. Gain local access: Obtain a low-privileged local account on a system where CODESYS Development System (version < 3.5.22.20) is being installed or will be installed by an administrator.
  2. Monitor for installation activity: Use process monitoring tools (e.g., Process Monitor on Windows) or file system watchers to detect when the CODESYS installer begins extracting files to the temporary directory.
  3. Identify the temporary directory: Observe the path of the temporary extraction directory (e.g., a subdirectory under %TEMP% or a system-wide temp path) and confirm it is accessible with low-privileged permissions.
  4. Prepare malicious payload: Craft a malicious executable or DLL that, when executed with elevated privileges, performs the desired action (e.g., adding a backdoor user, launching a reverse shell, or installing persistent malware).
  5. Exploit the TOCTOU window: After the installer verifies the integrity of extracted files but before it copies them to the final installation directory, rapidly replace the target file(s) in the temporary directory with the malicious payload using a script or tool that continuously polls and overwrites the file.
  6. Achieve privilege escalation: The installer copies the attacker-substituted malicious file to the final destination and executes it with elevated (administrator/SYSTEM) privileges, completing the privilege escalation (Github Advisory).

Indicators of compromise

  • File System: Unexpected or recently modified files in the CODESYS installation temporary directory (e.g., %TEMP%\CODESYS* or similar) during or immediately after an installation event; file timestamps inconsistent with the installation timeline.
  • Process: Unusual child processes spawned by the CODESYS installer process (e.g., msiexec.exe, setup.exe) such as cmd.exe, powershell.exe, or network tools; processes running at elevated privilege levels that were not expected post-installation.
  • Logs: Windows Security Event Log entries showing privilege use (Event ID 4672) or new account creation (Event ID 4720) coinciding with a CODESYS installation event; Windows Installer logs (%TEMP%\MSI*.log) showing file copy operations from unexpected source paths.
  • Network: Outbound connections from the newly installed CODESYS process or from processes spawned during installation to unknown external IP addresses.

Mitigation and workarounds

CODESYS has released version 3.5.22.20 of the Development System, which addresses this vulnerability by correcting the default permissions applied to the temporary extraction directory during installation (Github Advisory, CERTVDE Advisory). Organizations should update to version 3.5.22.20 or later as the primary remediation. As interim workarounds: restrict administrative installation privileges to trusted users only; apply file integrity monitoring on temporary directories during installation; and ensure that the system's temporary directories are configured with restrictive ACLs that prevent low-privileged users from writing or replacing files.

Community reactions

The vulnerability was assigned and disclosed by CERT@VDE, the coordinating PSIRT for industrial automation vendors, indicating standard responsible disclosure practices for OT/ICS software (CERTVDE Advisory). The advisory was also published to the ENISA European Vulnerability Database (EUVD-2026-31797). No notable public researcher commentary, social media discussion, or significant media coverage beyond standard vulnerability aggregator postings has been observed at this time.

Additional resources


SourceThis report was generated using AI

Related CODESYS Development System vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44469HIGH8.5
  • CODESYS Development System logoCODESYS Development System
  • cpe:2.3:a:codesys:development_system
NoYesMay 26, 2026
CVE-2026-44468HIGH8.5
  • CODESYS Development System logoCODESYS Development System
  • cpe:2.3:a:codesys:development_system
NoYesMay 26, 2026
CVE-2025-41700HIGH7.8
  • CODESYS Development System logoCODESYS Development System
  • cpe:2.3:a:codesys:development_system
NoYesDec 01, 2025
CVE-2023-5751HIGH7.8
  • CODESYS Development System logoCODESYS Development System
  • cpe:2.3:a:codesys:development_system
NoYesJun 04, 2024
CVE-2023-49675HIGH7.8
  • CODESYS Development System logoCODESYS Development System
  • cpe:2.3:a:codesys:development_system
NoNoMay 06, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management