IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Rockwell Automation ThinManager

HIGH
CVSS 8.1
Date 2026-07-23T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-11917 8.1 high
A path traversal security issue exists within Rockwell Automation ThinManager software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory.

// Remediations (7)

Patch: ThinManager Versions 13.2.0 - 13.2.4 --> 13.2.5
ThinManager Versions 13.2.0 - 13.2.4 --> 13.2.5
Mitigation: For more information, refer to Rockwell Automation's Securitry Advisory page.
For more information, refer to Rockwell Automation's Securitry Advisory page.
Patch: ThinManager Versions 13.0.0 - 13.0.7 --> 13.0.8
ThinManager Versions 13.0.0 - 13.0.7 --> 13.0.8
Patch: ThinManager Versions 13.1.0 - 13.1.5 --> 13.1.6
ThinManager Versions 13.1.0 - 13.1.5 --> 13.1.6
Mitigation: Users using the affected software, who are not able to upgrade to one of the corrected versions, sho
Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices.
Patch: ThinManager Versions 14.0.0 - 14.0.2 --> 14.0.3
ThinManager Versions 14.0.0 - 14.0.2 --> 14.0.3
Mitigation: Users using the affected software, should upgrade to one of the corrected versions as follows:
Users using the affected software, should upgrade to one of the corrected versions as follows:

// References