CVE-2026-8153
CVSS 9.8 CRITICAL: oS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows… EPSS 2% (76th percentile).
Vulnerabilities · 117 days ago
This is unauthenticated code execution on the robot controller itself, not just another exposed web service. If Polyscope 5 is compromised, an attacker can affect robot behavior and firmware integrity, and a network-only fix may not undo changes already made on the machine.
CISA and Universal Robots say CVE-2026-8153 is an OS command injection flaw in the Polyscope 5 Dashboard Server interface. It affects Polyscope 5 versions before 5.25.1, and Universal Robots has released 5.25.1 as the fixed version.
For manufacturing and critical infrastructure operators, the risk is persistent compromise of equipment that directly drives physical processes. That makes patch status and device integrity more important than treating this as a routine host hardening issue.
CVSS 9.8 CRITICAL: oS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows… EPSS 2% (76th percentile).
3 sources covering this story
Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control
An attacker can exploit the command injection flaw to gain remote access to robotic systems, causing significant disruption to the environment.
Critical Vulnerability Exposes Industrial Robot Fleets to Hacking
The vulnerability, CVE-2026-8153, affects Universal Robots PolyScope 5 and it can be exploited for OS command injection.
Universal Robots Polyscope 5 | CISA
Universal Robots Polyscope 5 Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and execute code.
Part of the PlainSec briefing for 2026-05-21