CVE-2026-6071 PUBLISHED

Code Execution Vulnerability in Arena®

Assigner: Rockwell
Reserved: 10.04.2026 Published: 03.09.2026 Updated: 03.09.2026

A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.5

Product Status

Vendor Rockwell Automation
Product Arena
Versions Default: unaffected
  • Version All versions 16.20.08 and prior is affected

References