Security/ siemens · ics-security · cisa · privilege-escalation

Siemens License Server Flaws Enable Root Access, File Theft

Two flaws in Siemens License Server let a local user become root or let a remote attacker read files on the box, and only a patch closes both.

Siemens shipped a fix for two License Server bugs that, chained together, take an attacker from network access to root control of the box.

CISA republished a Siemens ProductCERT advisory on August 13, 2026, covering two flaws in Siemens License Server (SLS). CVE-2026-69108 is a local privilege escalation caused by an insecure sudoers policy - a low-level misconfiguration that lets a local user run commands as root and plant malicious files, a medium-severity issue (CVSS 6.0) fixed in version 5.1. CVE-2026-69109 is a path traversal flaw that lets a remote, unauthenticated attacker read arbitrary files off the server, rated high severity (CVSS 7.5) and fixed in version 5.3. Both were reported to CISA by Siemens' own product security team.

License servers rarely make headlines, but they sit at a soft spot in industrial networks: often internet-facing or bridging IT and OT, and used worldwide across Siemens' industrial software customers. An unauthenticated file-read bug on its own is bad enough for leaking configuration data; paired with a local root-escalation flaw as sloppy as a bad sudoers entry, it is the kind of combination that turns a minor foothold into full compromise.

There is no evidence of active exploitation here, and Siemens patched both issues before CISA published. Still, a sudoers misconfiguration is the sort of bug that should not exist in 2026 - it is the industrial-control-systems equivalent of leaving the back door unlocked because the front door has a good camera.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →