← All Advisories

Rockwell ThinManager API path traversal allows authenticated attacker to write arbitrary files to restricted system directories

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-11917

Key Details

CVECVE-2026-11917
CVSS Score / Version7.2 (High) / CVSS v4.0
Updated2026-07-14
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

What to Know

A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-11917
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-11917