All stories
highDefensive GuidanceCVE-2026-11917

Authenticated attackers can write arbitrary files through path traversal in Rockwell ThinManager

An authenticated attacker can write arbitrary files to restricted system directories via a path traversal vulnerability in Rockwell Automation's FactoryTalk ThinManager. This flaw affects several major software versions and could allow an attacker to move outside the application's intended directory structure. Update to a patched version immediately to mitigate this risk.

Summary

A high-severity path traversal vulnerability has been identified in Rockwell Automation's FactoryTalk ThinManager. The issue, tracked as CVE-2026-11917, stems from improper limitations placed on file save operations within the software's API.

ThinManager functions as a centralized management tool for thin clients, delivering industrial visualization and application control across various devices. Because the vulnerability allows an attacker to manipulate file paths, they can bypass intended directory restrictions to place files in sensitive system locations.

Technical details

The vulnerability is classified as a CWE-22: Improper Limitation of a Pathname to a Restricted Directory. This occurs when an application accepts input that contains special characters or sequences (such as ../) which allow the user to navigate outside of the intended folder structure.

In the case of ThinManager, the flaw exists within its API. An authenticated attacker can exploit these improper file save limitations to write files to restricted system directories that are located outside of the application's designated storage area. This capability could lead to significant unauthorized changes to the underlying operating system or application environment.

Affected products and fixed versions

The vulnerability impacts several versions of ThinManager. Users should verify their current version and upgrade to one of the corrected releases listed below:

Version Range Status
13.0.0 - 13.0.7 Vulnerable
13.1.0 - 13.1.5 Vulnerable
13.2.0 - 13.2.4 Vulnerable
14.0.0 - 14.0.2 Vulnerable

Defender guidance

To mitigate this risk, prioritize upgrading ThinManager to a patched version as soon as possible. If an immediate upgrade is not feasible due to operational constraints, Rockwell Automation recommends implementing their established security best practices for your specific environment.

Since the exploit requires authentication, ensure that access to the ThinManager API and its associated management interfaces is strictly controlled. Monitor system logs for unusual file creation events or unexpected directory access patterns that deviate from standard thin client operations.

Sources

  1. https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05
  2. https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1782.html
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -