CVE-2026-69108
Received Received - Intake

Privilege Escalation in Siemens License Server

Vulnerability report for CVE-2026-69108, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Siemens AG

Description

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
siemens license_server to 5.1 (exc)
siemens license_server to 5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-69108 is a local privilege escalation vulnerability in Siemens License Server (SLS) affecting all versions before V5.1. It occurs due to an insecure sudoers policy, allowing attackers to execute arbitrary commands as root and potentially compromise the entire system.

Detection Guidance

Check the installed version of Siemens License Server (SLS) using commands like 'rpm -qa | grep license_server' or 'dpkg -l | grep license_server' on Linux systems. Verify if the version is below V5.1. Inspect sudoers configuration files for insecure policies using 'sudo -l' to list allowed commands for users.

Impact Analysis

An attacker could exploit this to gain full system access, execute malicious commands, and plant harmful files with root privileges. This could lead to data theft, system damage, or unauthorized control of the affected server.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements like GDPR (data protection) and HIPAA (health information security). Full system compromise may result in data breaches and regulatory penalties.

Mitigation Strategies

Immediately update Siemens License Server to version V5.1 or later. Restrict sudo privileges by reviewing and correcting sudoers policies. Ensure network access is protected and follow Siemens' Industrial Security guidelines.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69108. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart