← All Advisories

CODESYS Runtime Insufficient Authorization on User Account Deletion Allows Low-Privilege Remote User to Delete Any User

Last refreshed2026-10-07

Status: UPDATED  |  Advisory ID: CVE-2026-8046

Key Details

CVECVE-2026-8046
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-07-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-863 (Incorrect Authorization)
Exploitation prediction (EPSS)0.45% probability of exploitation in the next 30 days (37% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
CODESYSCODESYS Control RTE (SL)
CODESYSCODESYS Control RTE (for Beckhoff CX) SL
CODESYSCODESYS Control Win (SL)
CODESYSCODESYS HMI (SL)
CODESYSCODESYS Runtime Toolkit
CODESYSCODESYS Control for BeagleBone SL
CODESYSCODESYS Control for emPC-A/iMX6 SL
CODESYSCODESYS Control for IOT2000 SL
CODESYSCODESYS Control for Linux ARM SL
CODESYSCODESYS Control for Linux SL
CODESYSCODESYS Control for PFC100 SL
CODESYSCODESYS Control for PFC200 SL
CODESYSCODESYS Control for PLCnext SL
CODESYSCODESYS Control for Raspberry Pi SL
CODESYSCODESYS Control for WAGO Touch Panels 600 SL
CODESYSCODESYS Virtual Control SL
SubsystemsGeneral OT
SectorsMultiple

What to Know

The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges. (NVD)

What to Do

Monitor CODESYS's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-8046
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-8046