Published advisories
When we resolve a reported security issue, we publish an advisory here (identifier ESA-YYYY-NNN) so customers can assess their exposure and upgrade. Advisories are listed newest first.
ESA-2026-005
Published 2026-07-14
Residual SQL injection in device template lookups and list sorting
- Affected versions
- Versions before 2026-07-14
- Fixed in
- 2026-07-14
- Impact
- Medium
- CVSS
- 6.4 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N)
- Mitigation
- Update to version 2026-07-14 or later. No configuration change is required after updating. This is a follow-up to ESA-2026-002 that hardens two remaining query paths of the same class.
- Credit
- Internal security review
ESA-2026-004
Published 2026-07-14
Redundancy synchronization channel lacked mutual authentication
- Affected versions
- Versions before 2026-07-14
- Fixed in
- 2026-07-14
- Impact
- High
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Mitigation
- Update to version 2026-07-14 or later. After updating, set a Redundancy Shared Secret with the same value on both nodes in the redundancy settings to require authenticated synchronization, and keep the redundancy link on a dedicated, isolated network. Existing pairs continue to operate on the previous behaviour until the secret is configured.
- Credit
- Internal security review
ESA-2026-003
Published 2026-07-14
Project and library import could write files outside the intended folder
- Affected versions
- Versions before 2026-07-14
- Fixed in
- 2026-07-14
- Impact
- High
- CVSS
- 7.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
- Mitigation
- Update to version 2026-07-14 or later. No configuration change is required after updating. Importing projects and libraries remains restricted to administrators; continue to import archives only from trusted sources.
- Credit
- Internal security review
ESA-2026-002
Published 2026-07-14
Configuration and historian search filters could allow SQL injection
- Affected versions
- Versions before 2026-07-14
- Fixed in
- 2026-07-14
- Impact
- High
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
- Mitigation
- Update to version 2026-07-14 or later. No configuration change is required after updating. As a general precaution on systems that were reachable by untrusted or Guest users, review user accounts and rotate credentials.
- Credit
- Internal security review
ESA-2026-001
Published 2026-07-14
Database Query tool could access databases outside its intended scope
- Affected versions
- Versions before 2026-07-14
- Fixed in
- 2026-07-14
- Impact
- High
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
- Mitigation
- Update to version 2026-07-14 or later. After updating, review the Database Query Access settings on the Parameters page and list only the databases the project requires. Keep Allow all databases cleared unless unrestricted access is required.
- Credit
- Internal security review