Rockwell Automation ControlFLASH Installer Grants Elevated Permissions
CISA has issued an advisory for Rockwell Automation's ControlFLASH software, detailing a vulnerability that could allow attackers to execute arbitrary code.

CISA has alerted users to a critical vulnerability affecting Rockwell Automation's ControlFLASH software, specifically versions up to and including V15.07. The vulnerability, identified as CVE-2026-12663, stems from an insecure configuration within the software's installer.
The core of the issue lies in how the ControlFLASH installer handles directory permissions. It inadvertently grants write permissions to the "Everyone" group on a product installation directory. This oversight allows for potential arbitrary code execution on a target machine, operating at the same permission level as the currently logged-in user. While not remotely exploitable, a local attacker with initial access could leverage this flaw to escalate privileges and execute malicious commands.
Successful exploitation of this vulnerability could enable an attacker to run any commands or code of their choice on the affected system. The impact is significant for industrial control systems (ICS) environments, particularly within the Critical Manufacturing and Energy sectors, where Rockwell Automation products are widely deployed globally. The CVSS v3.1 score for this vulnerability is a HIGH 7.3, reflecting its potential severity.
Rockwell Automation has addressed this vulnerability by releasing version 15.08 of ControlFLASH. The company strongly encourages all users to update to this latest version to remediate the security risk. For organizations unable to immediately upgrade, Rockwell Automation provides a specific mitigation: removing the "Everyone" group's write permissions from the C:\Program Files (x86)\ControlFLASH\0001 directory. Detailed steps for this manual mitigation are available in their security advisories.
In addition to the direct mitigation, Rockwell Automation also recommends adhering to their general security best practices for industrial control systems. These practices often include network segmentation, access control, and regular security audits to minimize the attack surface. Further guidance can be found on Rockwell Automation's trust center.
CISA emphasizes the importance of defensive measures to reduce the risk of exploitation. Organizations are advised to conduct thorough impact analyses and risk assessments before implementing any security controls. CISA also points to its ICS cybersecurity recommended practices, including "Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies" and "Targeted Cyber Intrusion Detection and Mitigation Strategies," for proactive defense.
While no public exploitation of this specific vulnerability has been reported to CISA at this time, the nature of the flaw—allowing local privilege escalation—makes it a target for attackers seeking to gain deeper access within an ICS network. The vulnerability is categorized under CWE-306: Missing Authentication for Critical Function, highlighting the lack of proper authorization checks during the installation process.
This advisory serves as a reminder of the ongoing security challenges within the industrial automation landscape. Maintaining up-to-date software, applying patches promptly, and implementing robust security configurations are crucial for protecting critical infrastructure from potential cyber threats.