<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:55:27 +0000</lastBuildDate>
    <item>
      <title>Advisory2026-09_VDE-2026-055 — CODESYS Development System - Incorrect Default Permissions</title>
      <link>https://cve.radiocsirt.org/vuln/advisory2026-09_vde-2026-055</link>
      <description>&lt;p&gt;Two local privilege escalation vulnerabilities were identified in the CODESYS Development System. Specifically, the PackageManager and the IPM create temporary directories with insecure default permissions when executed with administrative privileges. This allows low-privileged local users to modify a temporary bootstrap file to force the deployment of arbitrary components, or to exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition to replace digitally verified installation files with malicious ones prior to installation. Both flaws bypass intended security boundaries during the installation of packages or add-ons.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Two local privilege escalation vulnerabilities were identified in the CODESYS Development System. Specifically, the PackageManager and the IPM create temporary directories with insecure default permissions when executed with administrative privileges. This allows low-privileged local users to modify a temporary bootstrap file to force the deployment of arbitrary components, or to exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition to replace digitally verified installation files with malicious ones prior to installation. Both flaws bypass intended security boundaries during the installation of packages or add-ons.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/advisory2026-09_vde-2026-055</guid>
    </item>
    <item>
      <title>EUVD-2026-321196</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-321196</link>
      <description>EUVD-2026-321196</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-321196</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44468</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44468</link>
      <description>&lt;p&gt;The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44468</guid>
    </item>
    <item>
      <title>GHSA-x347-p9xc-q762</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x347-p9xc-q762</link>
      <description>&lt;p&gt;The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x347-p9xc-q762</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1675 — CODESYS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1675</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CODESYS ausnutzen, um seine Privilegien zu erhöhen, um Daten zu manipulieren, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CODESYS ausnutzen, um seine Privilegien zu erhöhen, um Daten zu manipulieren, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1675</guid>
    </item>
  </channel>
</rss>
