highOther

Rockwell Automation ControlFLASH Insecure Installer Permissions (CVE-2026-12663)

First seen Sep 7, 2026 · Updated Sep 7, 2026 · CVSS 7.3

ICSSCADARockwell Automationlocal-privilege-escalationinsecure-permissionscritical-infrastructureCWE-306

Rockwell Automation ControlFLASH versions V15.07 and earlier contain a local privilege escalation vulnerability caused by the installer granting the 'Everyone' group write permissions on the product installation directory. A local attacker with limited privileges could exploit this to plant malicious code or binaries that execute at the logged-in user's permission level, enabling arbitrary command or code execution.

Technical Analysis

The vulnerability (CVE-2026-12663, CWE-306: Missing Authentication for Critical Function) stems from overly permissive file system ACLs set by the ControlFLASH installer, which grants the 'Everyone' group write access to the installation directory (e.g., C:\Program Files (x86)\ControlFLASH\0001). This allows any local user or process to modify or replace files within the directory, leading to arbitrary code execution when the application or its components are subsequently run or updated. Exploitation requires local access and user interaction (CVSS v3.1: AV:L/AC:L/PR:L/UI:R, 7.3 High; CVSS v4.0: 7.0 High), and there is no known public exploitation at this time. While this is an OT/ICS engineering workstation issue rather than a remote network vulnerability, environments where AI agents or automation tooling run on shared engineering workstations with ControlFLASH installed could see agent-assisted processes or credentials compromised if a low-privileged local attacker plants malicious payloads in the writable directory, warranting inclusion in agent-adjacent OT security reviews.

Affected Systems

Rockwell Automation ControlFLASH versions <=V15.07 (Windows-based ICS firmware update utility), typically deployed on engineering workstations in Critical Manufacturing, Energy, and Water/Wastewater sectors worldwide.

Indicators of Compromise

  • Not applicable — this is a vulnerability disclosure, not an active malware/campaign; no known IOCs reported.

Remediation Steps

  1. 1

    Upgrade ControlFLASH

    Update to ControlFLASH version 15.08 or later, which corrects the insecure permission issue.

  2. 2

    Remove Everyone group permissions

    For systems that cannot be upgraded, manually remove the 'Everyone' group's write access from the C:\Program Files (x86)\ControlFLASH\0001 folder via folder Properties > Security tab > Edit > remove Everyone group.

  3. 3

    Apply Rockwell security best practices

    Follow Rockwell Automation's published security best practice guidance for hardening ControlFLASH installations and related engineering workstations.

  4. 4

    Restrict local access to engineering workstations

    Limit local user privileges and physical/logical access to hosts running ControlFLASH to reduce the risk of local exploitation.

  5. 5

    Network segmentation

    Ensure ICS engineering workstations are isolated from business networks and the internet per CISA ICS defense-in-depth recommendations.

CVE / Advisory IDs

CVE-2026-12663

Industries Most Exposed

Critical ManufacturingEnergyWater and Wastewater

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.