CVE-2026-6071
Received Received - Intake

Remote Code Execution in DOE File Parser

Vulnerability report for CVE-2026-6071, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: Rockwell Automation

Description

A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a remote code execution issue in certain products when processing DOE files. An attacker could exploit it by tricking a user into visiting a malicious page or opening a malicious file, which would allow writing past an allocated object's boundary and executing code in the current process context.

Impact Analysis

If exploited, this vulnerability could allow an attacker to take control of your system, install malware, steal data, or perform other malicious actions within the context of your current user session. It requires user interaction like opening a file or visiting a webpage.

Mitigation Strategies

Apply vendor-provided patches or updates for the affected products. Avoid opening untrusted DOE files or visiting suspicious web pages. Implement network segmentation to limit exposure. Monitor for unusual process activity or unauthorized code execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6071. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart