CVE Explorer
CVE-2026-9128
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Studio 5000 Logix Designer","vendor":"Rockwell Automation","versions":[{"status":"affected","version":"V35.00, 34.00-34.02, 33.00-33.02, 32.00-32.04 and older"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f720a2dd7590852035794a26428909e01e6081bda2e1837f3918c8b39cfbf6c2 · sha256:badf99e3605e10ec… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":7.3,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f720a2dd7590852035794a26428909e01e6081bda2e1837f3918c8b39cfbf6c2 · sha256:badf99e3605e10ec… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-428","description":"CWE-428: Unquoted Search Path or Element","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f720a2dd7590852035794a26428909e01e6081bda2e1837f3918c8b39cfbf6c2 · sha256:badf99e3605e10ec… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1783.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f720a2dd7590852035794a26428909e01e6081bda2e1837f3918c8b39cfbf6c2 · sha256:badf99e3605e10ec… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.