CVE-2026-44468: Codesys Development System

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.

Affected products

  • Codesys Development System: before 3.5.22.20 (fixed in 3.5.22.20)

Published 2026-05-26. Last modified 2026-07-24.