A vulnerability (CVE-2026-12663) exists in Rockwell Automation ControlFLASH versions up to and including V15.07. The installer incorrectly grants write permissions to the 'Everyone' group on the product installation directory, enabling arbitrary code execution at the logged-in user's permission level. The vulnerability is classified as Missing Authentication for Critical Function (CWE-306) with a CVSS v3.1 score of 7.3 (HIGH). Affected critical infrastructure sectors include Critical Manufacturing, Energy, and Water and Wastewater. Rockwell Automation has released version 15.08 to address the issue. Users unable to upgrade can manually remove the 'Everyone' group from the ControlFLASH installation directory permissions. The vulnerability is not remotely exploitable and no known public exploitation has been reported. Rockwell Automation self-reported the vulnerability to CISA.