Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. | |
| Title | ControlFLASH ® – Improper Access Control | |
| First Time appeared |
Rockwell Automation
Rockwell Automation controlflash |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:rockwell_automation:controlflash_:v15.07_and_prior:*:*:*:*:*:*:* | |
| Vendors & Products |
Rockwell Automation
Rockwell Automation controlflash |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2026-09-01T13:30:42.933Z
Reserved: 2026-06-18T19:02:36.861Z
Link: CVE-2026-12663
No data.
Status : Received
Published: 2026-09-01T14:17:24.290
Modified: 2026-09-01T14:17:24.290
Link: CVE-2026-12663
No data.
OpenCVE Enrichment
No data.