CODESYS
CODESYS Installer Privilege Escalation Security Advisory
Pages
3
Time to read
3 mins
Publication
Language
English
Pages
3
Time to read
3 mins
Publication
Language
English
This document is a security advisory detailing a privilege escalation vulnerability in the CODESYS Installer, identified as CVE-2026-2364. The advisory outlines that due to a race condition, a local attacker with limited privileges can replace the verified downloaded setup before execution, allowing a malicious application to be executed with elevated rights. The document specifies that the update process runs with administrator privileges, which is a critical aspect of the vulnerability. It notes that the issue affects all versions of the CODESYS Installer prior to 2.6.1.0, while the update process for CODESYS Add-Ons remains unaffected. The advisory provides remediation steps, recommending users to update to version 2.6.1.0 and to consider manual downloads to avoid using the self-update mechanism. Additionally, it includes general security recommendations to enhance protection against such vulnerabilities.