Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in Siemens License Server

Siemens License Server (SLS) contains vulnerabilities allowing remote file disclosure (CVE-2026-69109) and local privilege escalation (CVE-2026-69108).

CVE search metadata

CVE search record: CVE-2026-69109. Severity: high. CVSS: 7.5. EPSS: 0.46%. KEV: no. Product: Siemens License Server (SLS). Brief: Multiple Vulnerabilities in Siemens License Server. Brief link: https://feed.craftedsignal.io/briefs/2026-08-siemens-license-server/

CVE search record: CVE-2026-69108. Severity: medium. CVSS: 6.0. EPSS: 0.11%. KEV: no. Product: Siemens License Server (SLS). Brief: Multiple Vulnerabilities in Siemens License Server. Brief link: https://feed.craftedsignal.io/briefs/2026-08-siemens-license-server/

Siemens License Server (SLS) is affected by two vulnerabilities that pose significant security risks to industrial and IT environments. CVE-2026-69108 is a local privilege escalation vulnerability caused by an insecure sudoers policy, which allows a local attacker to execute arbitrary commands with root privileges and create malicious files on the underlying system. CVE-2026-69109 is a path traversal vulnerability resulting from inadequate sanitization of user-supplied input, enabling an unauthenticated remote attacker to access arbitrary files on the host system. These vulnerabilities affect versions of Siemens License Server prior to V5.1 (for the privilege escalation flaw) and V5.3 (for the path traversal flaw). Defenders should prioritize patching to version 5.3 or later to mitigate these security gaps.

Impact

Successful exploitation of these vulnerabilities could result in full system compromise, unauthorized access to sensitive application data, and the potential for lateral movement within an organization's network. Given the role of license servers in industrial control system (ICS) environments, compromise of this service could impact the availability or integrity of license management for critical infrastructure deployments.

Recommendation

  • Upgrade all instances of Siemens License Server (SLS) to version 5.3 or later to remediate both CVE-2026-69108 and CVE-2026-69109.
  • Restrict network access to the Siemens License Server to only necessary management segments, isolating the server from public internet exposure as per CISA guidelines.
  • Implement strict ingress and egress filtering on firewall segments hosting the SLS to prevent unauthorized remote requests and potential data exfiltration resulting from path traversal attempts.
  • Conduct an audit of sudoers configuration files on systems hosting SLS to ensure least-privilege principles are enforced and to prevent unauthorized privilege escalation.

Immediate actions

Update Siemens License Server (SLS) to V5.3 or later

IT Operations 72h

Mitigations

Isolate license server from internet-facing network segments

immediate IT Operations

CVE-2026-69109