Skip to content
SiemensCVE-2026-69108

Siemens License Server (SLS): privilege escalation

High8.3CVE-2026-69108 · Published Aug 11, 2026 · updated Aug 28, 2026

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.

Siemens advisory

Affected versions

PackageAffectedFixed in
Siemens License Server (SLS)
Product
< V5.1V5.1
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-732

More Siemens advisories

All Siemens
Advisory
Siemens License Server (SLS): path traversal
High8.7Aug 11
Siemens Parasolid: out-of-bounds read
High7.3Aug 11
Siemens SIMATIC IoT2050 Advanced: remote code execution
Critical10.0Aug 11
Siemens Simcenter: code execution
High7.3Aug 11
Siemens Desigo: denial of service
Medium5.3Aug 11
Siemens Simcenter Femap: out-of-bounds read
High7.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.