Siemens SLS <5.3 Path Traversal: Arbitrary File Access
CVE-2026-69109 Published on August 11, 2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.
Weakness Type
Path Traversal: '.../...//'
The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
Affected Versions
Siemens License Server (SLS):- Before V5.3 is affected.