Remote file reading and root privilege escalation vulnerabilities found in Siemens License Server
Critical flaws in the Siemens License Server (SLS) could allow attackers to read arbitrary files remotely or gain full root access via local privilege escalation. Update your SLS instances to version 5.3 immediately to mitigate these risks.
Summary
The Siemens License Server (SLS), a central application supporting Siemens Advanced Licensing Technology (SALT) for various product families including EDA and PLM, contains two significant vulnerabilities. These flaws enable unauthorized file access and potential system-wide compromise through privilege escalation.
Siemens has released updated versions of the software to address these issues. Organizations running SLS should prioritize upgrading their environments to ensure that licensing daemons and associated utilities are not exposed to these attack vectors.
Technical details
The first vulnerability, CVE-2026-69109, is a path traversal flaw caused by insufficient sanitization of user input. This allows a remote attacker to access arbitrary files on the system. This vulnerability affects all versions prior to V5.3 and carries a CVSS score of 7.5 (High).
The second vulnerability, CVE-2026-69108, involves an insecure sudoers policy within the Siemens License Server. An attacker with high privileges can exploit this flaw to perform local privilege escalation. Successful exploitation allows for the execution of arbitrary commands and the planting of malicious files as root, resulting in full system compromise. This affects all versions prior to V5.1 and carries a CVSS score of 6.0 (Medium).
Affected products and fixed versions
The vulnerabilities impact the Siemens License Server (SLS), which includes the FlexNet License Manager Daemon (lmgrd), the Siemens vendor daemon (saltd), and various utilities.
| CVE | Severity | Fixed Version | Vulnerability Type |
|---|---|---|---|
| CVE-2026-69109 | 7.5 (High) | V5.3 | Path Traversal |
| CVE-2026-69108 | 6.0 (Medium) | V5.1 | Local Privilege Escalation |
Defender guidance
Update the Siemens License Server to at least version 5.3 to address both the path traversal and the sudoers policy vulnerabilities.
Protect network access to all licensing devices using appropriate access control mechanisms. Siemens recommends configuring environments according to their operational guidelines for Industrial Security. This includes following specific recommendations found in product manuals to maintain a protected IT environment.
