VORANT. Threat Intelligence Sign in Get the full feed

Siemens License Server flaws enable root compromise

routine vulnerability technology

Two vulnerabilities in Siemens License Server allow local privilege escalation to root and remote path traversal to read arbitrary files.

Siemens has disclosed two vulnerabilities in its License Server (SLS) product affecting versions prior to V5.1 and V5.3 respectively. CVE-2026-69108 stems from an insecure sudoers policy that allows a local attacker to execute arbitrary commands and plant malicious files as root, resulting in full system compromise. CVE-2026-69109 is a path traversal flaw caused by insufficient sanitization of user input, which could allow a remote attacker to access arbitrary files on the application.

Siemens has released fixed versions (V5.1 for the privilege escalation issue and V5.3 for the path traversal issue) and recommends all users update. The advisory, republished by CISA from Siemens ProductCERT's SSA-077553, notes the product is deployed worldwide across the Information Technology critical infrastructure sector. There is no indication of active exploitation; this is a vendor-driven patch advisory following standard coordinated disclosure through Siemens ProductCERT.

Mentioned in this report

Vulnerabilities CVE-2026-69108CVE-2026-69109

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-07

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free