Critical Path Traversal Vulnerability Found in Rockwell Automation ThinManager
CISA has issued an advisory for a critical path traversal vulnerability in Rockwell Automation ThinManager, potentially impacting critical infrastructure sectors.

Rockwell Automation's ThinManager software, a critical component for managing industrial control systems, is affected by a severe path traversal vulnerability, according to a recent advisory from the Cybersecurity and Infrastructure Security Agency (CISA).
The vulnerability, identified as CVE-2026-11917, stems from an "Improper Limitation of a Pathname to a Restricted Directory" within the software's API. This flaw allows an authenticated attacker to write arbitrary files to system directories outside of the application's intended scope. Such an attack could lead to the overwriting of critical system files, the introduction of malicious code, or other disruptive actions that could compromise the integrity and availability of industrial operations.
The CVSS v3.1 score for this vulnerability is a high 8.1, reflecting its significant potential impact. The vulnerability is categorized as HIGH severity, with an attack vector that does not require network exposure (AV:N), a low complexity (AC:L), and only requires the attacker to be authenticated with low privileges (PR:L). The impact on confidentiality is none (C:N), but the impact on integrity (I:H) and availability (A:H) is high, meaning an attacker could significantly alter or disable system functions.
Several versions of ThinManager are affected by this vulnerability, including versions 13.0.0 through 14.0.2. Specifically, the affected ranges are ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, and >=14.0.0|<14.0.2. These versions are deployed worldwide across critical infrastructure sectors such as Chemical, Critical Manufacturing, Energy, Food and Agriculture, and Water and Wastewater.
Rockwell Automation has released patches to address this vulnerability. Users are strongly advised to upgrade to the corrected versions: ThinManager 13.0.8 for versions 13.0.0-13.0.7, 13.1.6 for 13.1.0-13.1.5, 13.2.5 for 13.2.0-13.2.4, and 14.0.3 for 14.0.0-14.0.2. For organizations unable to upgrade immediately, Rockwell Automation recommends implementing their security best practices, which can be found on their security advisory page.
CISA emphasizes the importance of defensive measures for all control system devices. These include minimizing network exposure, ensuring devices are not accessible from the internet, and isolating control system networks behind firewalls. When remote access is necessary, secure methods like VPNs should be employed, with the understanding that VPNs themselves require regular updates and secure configurations.
While no public exploitation of CVE-2026-11917 has been reported to CISA at this time, the widespread use of ThinManager in critical infrastructure makes this a significant vulnerability. The potential for an authenticated attacker to gain a foothold and cause substantial damage underscores the need for prompt patching and adherence to security best practices.
This advisory serves as a crucial reminder for organizations operating industrial control systems to maintain vigilance regarding software updates and security configurations. Proactive risk assessment and the implementation of defense-in-depth strategies are essential for protecting these vital systems from potential cyber threats.