CODESYS
CODESYS Development System Security Advisory 2026-09
Pages
3
Time to read
3 mins
Publication
Language
English
Pages
3
Time to read
3 mins
Publication
Language
English
This document is a security advisory detailing two local privilege escalation vulnerabilities identified in the CODESYS Development System. The vulnerabilities arise from the PackageManager and the IPM creating temporary directories with insecure default permissions when executed with administrative privileges. This situation allows low-privileged local users to manipulate a temporary bootstrap file, potentially forcing the deployment of arbitrary components or exploiting a Time-of-Check to Time-of-Use (TOCTOU) race condition. Such exploitation can lead to the replacement of digitally verified installation files with malicious ones prior to installation, effectively bypassing intended security boundaries during package or add-on installations. The advisory specifies that all versions prior to 3.5.22.20 of the CODESYS Development System are affected and recommends updating to this version to remediate the vulnerabilities. Additionally, it provides general security recommendations to enhance the protection of the development and control systems.