highOther

Rockwell Automation ThinManager Path Traversal Vulnerability (CVE-2026-11917)

First seen Jul 24, 2026 · Updated Jul 24, 2026 · CVSS 8.1

ICSOTpath-traversalrockwell-automationthinmanagerindustrial-control-systemsCWE-22

A high-severity path traversal vulnerability (CVE-2026-11917) affects multiple versions of Rockwell Automation ThinManager, allowing an authenticated attacker to write arbitrary files to restricted system directories outside the application's intended scope. No public exploitation has been reported at this time, but organizations in critical infrastructure sectors using affected versions should prioritize patching.

Technical Analysis

CVE-2026-11917 is a Path Traversal vulnerability (CWE-22) in Rockwell Automation ThinManager's API, caused by improper limitation of file save operations, allowing an authenticated attacker to write arbitrary files to restricted system directories. The CVSS v3.1 score is 8.1 (HIGH: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H), and CVSS v4.0 score is 7.2, indicating network-exploitable attack vector with low privileges required and no user interaction, impacting integrity and availability but not confidentiality. Affected versions span ThinManager 13.0.0-13.0.7, 13.1.0-13.1.5, 13.2.0-13.2.4, and 14.0.0-14.0.2, with vendor patches available (13.0.8, 13.1.6, 13.2.5, 14.0.3). This is an OT/ICS-specific thin-client management platform vulnerability with no direct or plausible impact on AI agent systems, LLM tool use, or RAG pipelines, as ThinManager is a specialized industrial thin-client management product unrelated to typical agent infrastructure.

Affected Systems

Rockwell Automation ThinManager versions >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2

Indicators of Compromise

  • No specific IOCs published; no known public exploitation reported at this time.

Remediation Steps

  1. 1

    Upgrade ThinManager to patched version

    Upgrade affected ThinManager installations to versions 13.0.8, 13.1.6, 13.2.5, or 14.0.3 depending on current branch.

  2. 2

    Apply vendor security best practices

    For systems that cannot be immediately upgraded, follow Rockwell Automation's published security best practices guidance.

  3. 3

    Restrict network exposure

    Minimize network exposure for all control system devices, ensuring ThinManager and related ICS systems are not accessible from the internet.

  4. 4

    Network segmentation

    Place control system networks and remote devices behind firewalls and isolate them from business networks.

  5. 5

    Secure remote access

    Use VPNs or other secure remote access methods when remote access to ICS environments is required, and keep VPN software updated.

  6. 6

    Monitor and report

    Monitor for suspicious activity related to ThinManager and report any suspected malicious activity to CISA for tracking and correlation.

CVE / Advisory IDs

CVE-2026-11917

Industries Most Exposed

ChemicalCritical ManufacturingEnergyFood and AgricultureWater and Wastewater

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.