SiemensCVE-2026-69108
Siemens License Server (SLS): privilege escalation
High8.3CVE-2026-69108 · Published Aug 11, 2026 · updated Aug 28, 2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Siemens License Server (SLS) Product | < V5.1 | V5.1 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-732
More Siemens advisories
All Siemens| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Siemens License Server (SLS): path traversal | High8.7 | V5.3 |
| Aug 11 | Siemens Parasolid: out-of-bounds read | High7.3 | V38.0.235+1 more |
| Aug 11 | Siemens SIMATIC IoT2050 Advanced: remote code execution | Critical10.0 | V4.3.4.1 |
| Aug 11 | Siemens Simcenter: code execution | High7.3 | V2606+1 more |
| Aug 11 | Siemens Desigo: denial of service | Medium5.3 | V01.21.233.16-7862+2 more |
| Aug 11 | Siemens Simcenter Femap: out-of-bounds read | High7.3 | V2606.0001 |