CVE-2026-69108 PUBLISHED

Assigner: siemens
Reserved: 03.08.2026 Published: 11.08.2026 Updated: 11.08.2026

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.3

Product Status

Vendor Siemens
Product Siemens License Server (SLS)
Versions Default: unknown
  • affected from 0 to V5.1 (excl.)

References

Problem Types

  • CWE-732: Incorrect Permission Assignment for Critical Resource CWE