Rockwell Automation ControlFLASH Insecure Installer Permissions (CVE-2026-12663)
First seen Sep 7, 2026 · Updated Sep 7, 2026 · CVSS 7.3
Rockwell Automation ControlFLASH versions V15.07 and earlier contain a local privilege escalation vulnerability caused by the installer granting the 'Everyone' group write permissions on the product installation directory. A local attacker with limited privileges could exploit this to plant malicious code or binaries that execute at the logged-in user's permission level, enabling arbitrary command or code execution.
Technical Analysis
The vulnerability (CVE-2026-12663, CWE-306: Missing Authentication for Critical Function) stems from overly permissive file system ACLs set by the ControlFLASH installer, which grants the 'Everyone' group write access to the installation directory (e.g., C:\Program Files (x86)\ControlFLASH\0001). This allows any local user or process to modify or replace files within the directory, leading to arbitrary code execution when the application or its components are subsequently run or updated. Exploitation requires local access and user interaction (CVSS v3.1: AV:L/AC:L/PR:L/UI:R, 7.3 High; CVSS v4.0: 7.0 High), and there is no known public exploitation at this time. While this is an OT/ICS engineering workstation issue rather than a remote network vulnerability, environments where AI agents or automation tooling run on shared engineering workstations with ControlFLASH installed could see agent-assisted processes or credentials compromised if a low-privileged local attacker plants malicious payloads in the writable directory, warranting inclusion in agent-adjacent OT security reviews.
Affected Systems
Rockwell Automation ControlFLASH versions <=V15.07 (Windows-based ICS firmware update utility), typically deployed on engineering workstations in Critical Manufacturing, Energy, and Water/Wastewater sectors worldwide.
Indicators of Compromise
- Not applicable — this is a vulnerability disclosure, not an active malware/campaign; no known IOCs reported.
Remediation Steps
- 1
Upgrade ControlFLASH
Update to ControlFLASH version 15.08 or later, which corrects the insecure permission issue.
- 2
Remove Everyone group permissions
For systems that cannot be upgraded, manually remove the 'Everyone' group's write access from the C:\Program Files (x86)\ControlFLASH\0001 folder via folder Properties > Security tab > Edit > remove Everyone group.
- 3
Apply Rockwell security best practices
Follow Rockwell Automation's published security best practice guidance for hardening ControlFLASH installations and related engineering workstations.
- 4
Restrict local access to engineering workstations
Limit local user privileges and physical/logical access to hosts running ControlFLASH to reduce the risk of local exploitation.
- 5
Network segmentation
Ensure ICS engineering workstations are isolated from business networks and the internet per CISA ICS defense-in-depth recommendations.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.