
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-44469 is a local privilege escalation vulnerability in CODESYS Development System caused by incorrect default permissions on a temporary directory used during administrative installation. The affected product extracts installation files to a world-writable (or insufficiently restricted) temporary directory, enabling a TOCTOU (Time-of-Check to Time-of-Use) race condition that a low-privileged local attacker can exploit to replace verified files with malicious ones before they are installed. Affected versions span from 3.0.0.0 up to (but not including) 3.5.22.20. The vulnerability was published on May 26, 2026, with a CVSS v3.1 base score of 7.0 (High) and a CVSS v4.0 base score of 8.5 (High) (Github Advisory).
The root cause is classified as CWE-276 (Incorrect Default Permissions): during administrative installation, CODESYS Development System extracts files to a temporary directory without applying restrictive access controls, leaving those files modifiable by low-privileged users (Github Advisory). The attack exploits a TOCTOU race condition — after the installer verifies the integrity of extracted files but before it copies them to their final destination, an attacker can swap the verified files with malicious payloads. The exploitation window is described as "practical," meaning it is large enough to be reliably exploited without requiring highly precise timing. The attack vector is local, requires low privileges, and no user interaction beyond the legitimate administrator initiating the installation process.
Successful exploitation results in local privilege escalation, granting the attacker high confidentiality, integrity, and availability impact on the vulnerable system. A low-privileged local user can elevate to the privilege level under which the installer runs (typically SYSTEM or administrator), enabling full control over the affected host. This could allow an attacker to install persistent malware, access sensitive engineering data within CODESYS projects, or pivot to connected industrial control systems and OT environments (Github Advisory).
There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation at the time of publication (Github Advisory). The EPSS score is approximately 0.011% (1st percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. While the exploitation window is described as practical, the local access requirement limits the attacker pool.
%TEMP% or a system-wide temp path) and confirm it is accessible with low-privileged permissions.%TEMP%\CODESYS* or similar) during or immediately after an installation event; file timestamps inconsistent with the installation timeline.msiexec.exe, setup.exe) such as cmd.exe, powershell.exe, or network tools; processes running at elevated privilege levels that were not expected post-installation.%TEMP%\MSI*.log) showing file copy operations from unexpected source paths.CODESYS has released version 3.5.22.20 of the Development System, which addresses this vulnerability by correcting the default permissions applied to the temporary extraction directory during installation (Github Advisory, CERTVDE Advisory). Organizations should update to version 3.5.22.20 or later as the primary remediation. As interim workarounds: restrict administrative installation privileges to trusted users only; apply file integrity monitoring on temporary directories during installation; and ensure that the system's temporary directories are configured with restrictive ACLs that prevent low-privileged users from writing or replacing files.
The vulnerability was assigned and disclosed by CERT@VDE, the coordinating PSIRT for industrial automation vendors, indicating standard responsible disclosure practices for OT/ICS software (CERTVDE Advisory). The advisory was also published to the ENISA European Vulnerability Database (EUVD-2026-31797). No notable public researcher commentary, social media discussion, or significant media coverage beyond standard vulnerability aggregator postings has been observed at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."