Causal model
What has to happen for this consequence to hold?
3 candidate paths · explicit source, inference, and assumption boundaries.
Safety · Co-dominant path
Device-control safety
Operating-system command execution can alter the motion of an industrial cobot working near people, creating a credible risk of collision or injury.
Cross-domain authority chain
Crosses network to controller to physical and safety boundaries and bridges into actuation.
EvidenceNo direct citation — inspect the declared inference or assumption.
Severe therapy or actuation consequence
Operating-system command execution can alter the motion of an industrial cobot working near people, creating a credible risk of collision or injury.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
Operating-system command execution can alter the motion of an industrial cobot working near people, creating a credible risk of collision or injury.
EvidenceNo direct citation — inspect the declared inference or assumption.
Patch, reset, or reconfiguration
Software patch (5.25.1) plus segmentation.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
Default-exposed network service.
- Execution complexity
EC 4 - Straightforward operation
Single low-complexity request, without authentication.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Operating-system command execution can alter the motion of an industrial cobot working near people, creating a credible risk of collision or injury.
- Data / perception
DP 3 - Sensitive device or personal data
Controller exposes program logic and operational state.
- Authority
AT 3 - Administrative or command authority
Arbitrary operating system command execution is service and administrator-level control over the controller and its motion programs (not a signing and firmware-update trust root).
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Crosses network to controller to physical and safety boundaries and bridges into actuation.
- Reuse scale
SR 2 - Repeatable method
The dashboard command technique can be reused against controllers that expose the same unauthenticated service.
- Execution scale
SX 4 - Remote fleet-scale execution
Scriptable across every reachable controller of same version.
- Recovery burden
OR 2 - Patch, reset, or reconfiguration
Software patch (5.25.1) plus segmentation.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandEMERGENCY
- No adjustment
The EMERGENCY base band remains final because no separate cap or systemic uplift applies. Operating-system command execution can alter the motion of an industrial cobot working near people, creating a credible risk of collision or injury.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:3/CH:4/SR:2/SX:4/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →Systemic · Co-dominant path
Fleet control plane
The same operating-system command authority can modify programs and controller behavior across every reachable affected robot, without exposing a firmware-signing key.
Network-reachable without prior access
The Dashboard Server is exposed on the controller network by default and accepts the vulnerable request without authentication.
EvidenceNVD
Cross-domain authority chain
Cross-domain reusable bridge (one exploit to many controllers).
EvidenceNo direct citation — inspect the declared inference or assumption.
Administrative or command authority
The same operating-system command authority can modify programs and controller behavior across every reachable affected robot, without exposing a firmware-signing key.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet control plane
The same operating-system command authority can modify programs and controller behavior across every reachable affected robot, without exposing a firmware-signing key.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Recovery requires patching and segmenting every controller across the deployment (fleet action).
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
The Dashboard Server is exposed on the controller network by default and accepts the vulnerable request without authentication.
- Execution complexity
EC 4 - Straightforward operation
One reproducible command-injection request reaches the controller operating system; no multi-stage exploit is required.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 3 - Credible safety consequence
Fleet-wide motion influence reduces safety margins across many cells but per-cell severe harm is captured in the safety path.
- Data / perception
DP 3 - Sensitive device or personal data
Process and program data across the fleet.
- Authority
AT 3 - Administrative or command authority
The same operating-system command authority can modify programs and controller behavior across every reachable affected robot, without exposing a firmware-signing key.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Cross-domain reusable bridge (one exploit to many controllers).
- Reuse scale
SR 3 - Portable product-class technique
Shared software version and exploit portability deployment-wide.
- Execution scale
SX 4 - Remote fleet-scale execution
The injection request can be scripted across reachable affected controllers without a physical visit to each robot cell.
- Recovery burden
OR 3 - Coordinated operational recovery
Recovery requires patching and segmenting every controller across the deployment (fleet action).
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandEMERGENCY
- No adjustment
The EMERGENCY base band remains final because no separate cap or systemic uplift applies. The same operating-system command authority can modify programs and controller behavior across every reachable affected robot, without exposing a firmware-signing key.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:4/EX:4/PH:3/DP:3/AT:3/CH:4/SR:3/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLERead the scoring method →Authority · Co-dominant path
Account authority
The attacker gains operating-system command authority over the controller and can modify robot programs and configuration, but not the vendor signing root.
Reusable multi-stage bridge
Controller takeover is a strong pivot into both safety and fleet paths.
EvidenceNo direct citation — inspect the declared inference or assumption.
Administrative or command authority
The attacker gains operating-system command authority over the controller and can modify robot programs and configuration, but not the vendor signing root.
EvidenceNo direct citation — inspect the declared inference or assumption.
Account authority
The attacker gains operating-system command authority over the controller and can modify robot programs and configuration, but not the vendor signing root.
EvidenceNo direct citation — inspect the declared inference or assumption.
Patch, reset, or reconfiguration
Software patch plus port and network restriction.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
Unauthenticated network surface.
- Execution complexity
EC 4 - Straightforward operation
Single low-complexity injection.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Availability and workflow disruption of the controller at this terminal (severe actuation harm scored separately).
- Data / perception
DP 3 - Sensitive device or personal data
Exposes program logic, process data, and connected I and O state.
- Authority
AT 3 - Administrative or command authority
The attacker gains operating-system command authority over the controller and can modify robot programs and configuration, but not the vendor signing root.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
Controller takeover is a strong pivot into both safety and fleet paths.
- Reuse scale
SR 2 - Repeatable method
Version-shared reachability.
- Execution scale
SX 4 - Remote fleet-scale execution
Remotely scriptable across reachable targets.
- Recovery burden
OR 2 - Patch, reset, or reconfiguration
Software patch plus port and network restriction.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandEMERGENCY
- No adjustment
The EMERGENCY base band remains final because no separate cap or systemic uplift applies. The attacker gains operating-system command authority over the controller and can modify robot programs and configuration, but not the vendor signing root.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:3/CH:3/SR:2/SX:4/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the safety transition before acting on the band.
Triage beyond the first device: verify whether the reusable condition, propagation mechanism, and recovery dependency actually exist across the deployment.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVE recordsCVE-2026-8153
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Universal Robots PolyScope 5 Dashboard Server OS command injection (CVE-2026-8153) at EMERGENCY — the worst of 3 risk paths (safety, authority). The dominant consequence is influence over a safety-relevant actuation.
Vulnerability
Universal Robots PolyScope 5 Dashboard Server OS command injection (CVE-2026-8153). Reported attack vector: Network.
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → EMERGENCY
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:3/CH:4/SR:2/SX:4/OR:2/EV:2/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=CRITICAL · AT=CRITICAL → base EMERGENCY · uplift fleet-reachable authority → assessed EMERGENCY.
Unauthenticated network-reachable OS command injection (AV:N/AC:L/PR:N) on the PolyScope controller that drives a collaborative arm operating near humans. RE:4 default-exposed network service; EC:4 single low-complexity request, no auth. AT:3 arbitrary OS command execution = service/admin-level control over the controller and its motion programs (not a signing/OTA trust root). PH:4 OS-level control can alter motion of an industrial cobot designed to work near people -> credible injury/dangerous actuation. DP:3 controller exposes program logic and operational state. CH:4 crosses network->controller->physical/safety boundaries and bridges into actuation. SX:4 scriptable across every reachable controller of same version; SR:2 same software version reuse, not a shared secret/key. OR:2 software patch (5.25.1) plus segmentation; no hardware recall. EV:2 vendor+CISA report-backed, no public weaponized PoC. Physical effect inferred from arm control, so EV stays modelled/report-backed.
FLEET_CONTROL_PLANE → EMERGENCY
CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:4/EX:4/PH:4/DP:3/AT:3/CH:4/SR:3/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=CRITICAL · AT=CRITICAL → base EMERGENCY · uplift fleet-reachable authority → assessed EMERGENCY.
Cobots deploy in fleets across cells/lines on flat factory networks; an unauthenticated network RCE is scriptable and self-propagatable to every reachable controller of the same PolyScope version. RE:4 network-default-exposed; EC:4 trivial reproducible exploitation. AT:3 controller-level command authority replicated fleet-wide (not OTA/signing root, so not 4). PH:3 fleet-wide motion influence reduces safety margins across many cells but per-cell severe harm is captured in the safety path. DP:3 process/program data across the fleet. CH:4 cross-domain reusable bridge (one exploit -> many controllers). SR:3 shared software version/exploit portability deployment-wide; SX:4 fleet-scale remote execution without per-device physical access. OR:3 recovery requires patching/segmenting every controller across the deployment (fleet action). EV:2 report-backed advisory, no field-confirmed worm.
ACCOUNT_AUTHORITY → EMERGENCY
CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:3/CH:3/SR:2/SX:4/OR:2/EV:2/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=CRITICAL · AT=CRITICAL → base EMERGENCY · uplift fleet-reachable authority → assessed EMERGENCY.
Direct terminal of the flaw itself: full compromise (C:H/I:H/A:H) of the controller OS with no credentials. RE:4 unauthenticated network surface; EC:4 single low-complexity injection. AT:3 attacker gains arbitrary OS command authority over the controller (service/admin-level), able to modify config and programs; not a signing/identity root so not 4. PH:2 availability/workflow disruption of the controller at this terminal (severe actuation harm scored separately). DP:3 exposes program logic, process data, and connected I/O state. CH:3 controller takeover is a strong pivot into both safety and fleet paths. SR:2 version-shared reachability; SX:4 remotely scriptable across reachable targets. OR:2 software patch plus port/network restriction. EV:2 vendor and CISA confirmed, report-backed.
Published baseline
- v3.1 9.8 CRITICAL —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H— CNA via NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0027 (“Universal Robots PolyScope 5 Dashboard Server OS command injection (CVE-2026-8153)”), paths.cfse.ai/CPATH-2026-0027 (published 2026-06-03).