CVE-2026-8153
CVSS 9.8 CRITICAL: oS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows… EPSS 2% (76th percentile).
Vulnerabilities & Exploits · IoT / OT Attack
This is unauthenticated code execution on the robot controller itself, not just another exposed web service. If Polyscope 5 is compromised, an attacker can affect robot behavior and firmware integrity, and a network-only fix may not undo changes already made on the machine.
CISA and Universal Robots say CVE-2026-8153 is an OS command injection flaw in the Polyscope 5 Dashboard Server interface. It affects Polyscope 5 versions before 5.25.1, and Universal Robots has released 5.25.1 as the fixed version.
For manufacturing and critical infrastructure operators, the risk is persistent compromise of equipment that directly drives physical processes. That makes patch status and device integrity more important than treating this as a routine host hardening issue.
3 sources · May 20
CVSS 9.8 CRITICAL: oS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows… EPSS 2% (76th percentile).
Dark Reading
Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control
An attacker can exploit the command injection flaw to gain remote access to robotic systems, causing significant disruption to the environment.
originalSecurityWeek
Critical Vulnerability Exposes Industrial Robot Fleets to Hacking
The vulnerability, CVE-2026-8153, affects Universal Robots PolyScope 5 and it can be exploited for OS command injection.
originalCISA Advisories
Universal Robots Polyscope 5 | CISA
Universal Robots Polyscope 5 Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and execute code.
originalPart of the PlainSec briefing for 2026-05-21
Every edition of this story: Robot Controller Flaw Can Alter Physical Process Behavior