Rockwell ThinManager path traversal flaw patched
A path traversal vulnerability in Rockwell Automation ThinManager lets authenticated attackers write arbitrary files outside intended directories; patches available.
CISA and Rockwell Automation disclosed a path traversal vulnerability (CVE-2026-11917) in ThinManager, software used to manage thin clients in industrial environments across chemical, critical manufacturing, energy, food and agriculture, and water/wastewater sectors worldwide. The flaw stems from improper limitation of file save operations within the application's API, allowing an authenticated attacker to write arbitrary files to restricted system directories outside the application's intended directory (CWE-22).
Multiple ThinManager version branches are affected, including 13.0.0-13.0.6, 13.1.0-13.1.4, 13.2.0-13.2.3, and 14.0.0-14.0.1. Rockwell has released corrected versions (13.0.8, 13.1.6, 13.2.5, and 14.0.3) addressing the issue. CISA reports no known public exploitation of this vulnerability at this time and credits Rockwell Automation for responsibly reporting it.
Organizations using affected versions should prioritize upgrading to the patched releases. Where immediate patching isn't feasible, CISA recommends standard ICS defense-in-depth measures including network segmentation, isolating control system networks from business networks and the internet, and using secure remote access methods such as VPNs.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free