All stories
highDefensive GuidanceCVE-2026-69108CVE-2026-69109

Remote file reading and root privilege escalation vulnerabilities found in Siemens License Server

Critical flaws in the Siemens License Server (SLS) could allow attackers to read arbitrary files remotely or gain full root access via local privilege escalation. Update your SLS instances to version 5.3 immediately to mitigate these risks.

Summary

The Siemens License Server (SLS), a central application supporting Siemens Advanced Licensing Technology (SALT) for various product families including EDA and PLM, contains two significant vulnerabilities. These flaws enable unauthorized file access and potential system-wide compromise through privilege escalation.

Siemens has released updated versions of the software to address these issues. Organizations running SLS should prioritize upgrading their environments to ensure that licensing daemons and associated utilities are not exposed to these attack vectors.

Technical details

The first vulnerability, CVE-2026-69109, is a path traversal flaw caused by insufficient sanitization of user input. This allows a remote attacker to access arbitrary files on the system. This vulnerability affects all versions prior to V5.3 and carries a CVSS score of 7.5 (High).

The second vulnerability, CVE-2026-69108, involves an insecure sudoers policy within the Siemens License Server. An attacker with high privileges can exploit this flaw to perform local privilege escalation. Successful exploitation allows for the execution of arbitrary commands and the planting of malicious files as root, resulting in full system compromise. This affects all versions prior to V5.1 and carries a CVSS score of 6.0 (Medium).

Affected products and fixed versions

The vulnerabilities impact the Siemens License Server (SLS), which includes the FlexNet License Manager Daemon (lmgrd), the Siemens vendor daemon (saltd), and various utilities.

CVE Severity Fixed Version Vulnerability Type
CVE-2026-69109 7.5 (High) V5.3 Path Traversal
CVE-2026-69108 6.0 (Medium) V5.1 Local Privilege Escalation

Defender guidance

Update the Siemens License Server to at least version 5.3 to address both the path traversal and the sudoers policy vulnerabilities.

Protect network access to all licensing devices using appropriate access control mechanisms. Siemens recommends configuring environments according to their operational guidelines for Industrial Security. This includes following specific recommendations found in product manuals to maintain a protected IT environment.

Sources

  1. https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-07
  2. https://cert-portal.siemens.com/productcert/html/ssa-077553.html
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -