Siemens License Server Patched for Critical Privilege Escalation and Path Traversal Vulnerabilities
Siemens has released updates for the Siemens License Server (SLS) to address two actively tracked vulnerabilities. CVE-2026-69108 is a local privilege escalation flaw stemming from an insecure sudoers policy that could allow an attacker to execute arbitrary commands as root. CVE-2026-69109 is a path traversal vulnerability that could enable a remote attacker to read arbitrary files on the system. Both flaws affect SLS versions prior to 5.1 and 5.3 respectively, and Siemens recommends immediate updating to the latest released versions.