CVE-2026-79625: CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in CODESYS Control RTE (SL)
Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.
AI Analysis
Technical Summary
The vulnerability in CODESYS Control RTE (SL) involves improper synchronization when multiple clients send concurrent monitoring requests. This race condition (CWE-362) can lead to incorrect reads or writes or corruption of internal memory structures. An authenticated attacker with monitoring access can exploit this flaw to disrupt data integrity or cause denial-of-service conditions. The affected versions are from 3.0.0.0 up to but not including 3.5.22.40 and from 3.5.0.0 up to but not including 4.23.0.0. No explicit patch or remediation details are provided in the input data.
Potential Impact
Exploitation allows an authenticated remote attacker with monitoring access to cause incorrect data processing or denial-of-service by triggering race conditions in the monitoring functionality. This can affect the reliability and availability of the affected CODESYS Control RTE (SL) systems.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict monitoring access to trusted users only and avoid concurrent monitoring requests from multiple clients to reduce the risk of exploitation.
CVE-2026-79625: CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in CODESYS Control RTE (SL)
Description
Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.
CVSS v4.0
Score 7.2high
Affected software
CODESYS
Control RTE (SL)
CODESYS
Control RTE (for Beckhoff CX) SL
CODESYS
Control Win (SL)
CODESYS
Runtime Toolkit
CODESYS
Safety SIL2
CODESYS
HMI (SL)
CODESYS
Development System 3
CODESYS
Control for BeagleBone SL
CODESYS
Control for emPC-A/iMX6 SL
CODESYS
Control for IOT2000 SL
CODESYS
Control for Linux ARM SL
CODESYS
Control for Linux SL
CODESYS
Control for PFC100 SL
CODESYS
Control for PFC200 SL
CODESYS
Control for PLCnext SL
CODESYS
Control for Raspberry Pi SL
CODESYS
Control for WAGO Touch Panels 600 SL
CODESYS
Virtual Control SL
pkg:github/codesys/Control-RTE-SLRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in CODESYS Control RTE (SL) involves improper synchronization when multiple clients send concurrent monitoring requests. This race condition (CWE-362) can lead to incorrect reads or writes or corruption of internal memory structures. An authenticated attacker with monitoring access can exploit this flaw to disrupt data integrity or cause denial-of-service conditions. The affected versions are from 3.0.0.0 up to but not including 3.5.22.40 and from 3.5.0.0 up to but not including 4.23.0.0. No explicit patch or remediation details are provided in the input data.
Potential Impact
Exploitation allows an authenticated remote attacker with monitoring access to cause incorrect data processing or denial-of-service by triggering race conditions in the monitoring functionality. This can affect the reliability and availability of the affected CODESYS Control RTE (SL) systems.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict monitoring access to trusted users only and avoid concurrent monitoring requests from multiple clients to reduce the risk of exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERTVDE
- Date Reserved
- 2026-08-25T08:46:38.207Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abcdbaa0df196e1a9d76175
Added to database: 09/30/2026, 09:51:38 UTC
Last enriched: 09/30/2026, 09:57:45 UTC
Last updated: 09/30/2026, 13:03:41 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.