CVE-2026-6071
moderateOut-of-bounds write RCE in Rockwell Automation Arena via malicious DOE files
CVE-2026-6071 is an out-of-bounds write (CWE-787) in Rockwell Automation's affected products — most plausibly the Arena simulation software, whose native model format is the DOE file named in the advisory — that occurs when parsing DOE files and allows an attacker to write past the end of an allocated object and execute code in the context of the current process. Exploitation requires user interaction: a legitimate user must open a malicious DOE file or visit a malicious page, which is reflected in the CVSS 4.0 score of 7.5 (High) with network attack vector, high attack complexity, a prerequisite attack condition, and active user interaction. An attacker who succeeds gains arbitrary code execution with the privileges of the user running the software. Users running affected versions are affected; the exact affected version ranges are not enumerated in the available data and must be confirmed in the Rockwell Automation advisory. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS assigns a 0.4% probability of exploitation in the next 30 days (37th percentile).
What to do: Check installed Arena versions against the Rockwell Automation security advisory and upgrade to a fixed release as soon as one is published. Until then, do not open DOE files from untrusted or unexpected sources (email attachments, downloads, shared drives) and treat DOE files delivered via web pages as untrusted. Because exploitation depends on user action, brief everyone who uses Arena on the risk of opening untrusted model files and watch for unexpected Arena process crashes or child-process spawns.
| Rockwell Automation Arena simulation software (parses DOE model files) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.
- Weakness
- CWE-787
- Vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.