CPATH-2026-0027 · Robotics / humanoid

Universal Robots PolyScope 5 Dashboard Server OS command injection (CVE-2026-8153)

Two or more co-dominant consequence paths connect the public security record to a provisional EMERGENCY consequence band.

Candidate bandEMERGENCY
Co-dominant pathsDevice-control safety + Fleet control plane + Account authority

These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

3 candidate paths · explicit source, inference, and assumption boundaries.

Safety · Co-dominant path

Device-control safety

Operating-system command execution can alter the motion of an industrial cobot working near people, creating a credible risk of collision or injury.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    Default-exposed network service.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Crosses network to controller to physical and safety boundaries and bridges into actuation.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Severe therapy or actuation consequence

    Operating-system command execution can alter the motion of an industrial cobot working near people, creating a credible risk of collision or injury.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Operating-system command execution can alter the motion of an industrial cobot working near people, creating a credible risk of collision or injury.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Software patch (5.25.1) plus segmentation.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

Default-exposed network service.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Single low-complexity request, without authentication.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Operating-system command execution can alter the motion of an industrial cobot working near people, creating a credible risk of collision or injury.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Controller exposes program logic and operational state.

Model inference
AuthorityAT 3
Administrative or command authority

Arbitrary operating system command execution is service and administrator-level control over the controller and its motion programs (not a signing and firmware-update trust root).

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Crosses network to controller to physical and safety boundaries and bridges into actuation.

Model inference
Reuse scaleSR 2
Repeatable method

The dashboard command technique can be reused against controllers that expose the same unauthenticated service.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Scriptable across every reachable controller of same version.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Software patch (5.25.1) plus segmentation.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandEMERGENCY
  2. No adjustment

    The EMERGENCY base band remains final because no separate cap or systemic uplift applies. Operating-system command execution can alter the motion of an industrial cobot working near people, creating a credible risk of collision or injury.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:3/CH:4/SR:2/SX:4/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Systemic · Co-dominant path

Fleet control plane

The same operating-system command authority can modify programs and controller behavior across every reachable affected robot, without exposing a firmware-signing key.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    The Dashboard Server is exposed on the controller network by default and accepts the vulnerable request without authentication.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Cross-domain reusable bridge (one exploit to many controllers).

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Administrative or command authority

    The same operating-system command authority can modify programs and controller behavior across every reachable affected robot, without exposing a firmware-signing key.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Fleet control plane

    The same operating-system command authority can modify programs and controller behavior across every reachable affected robot, without exposing a firmware-signing key.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Recovery requires patching and segmenting every controller across the deployment (fleet action).

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The Dashboard Server is exposed on the controller network by default and accepts the vulnerable request without authentication.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

One reproducible command-injection request reaches the controller operating system; no multi-stage exploit is required.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 3
Credible safety consequence

Fleet-wide motion influence reduces safety margins across many cells but per-cell severe harm is captured in the safety path.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Process and program data across the fleet.

Model inference
AuthorityAT 3
Administrative or command authority

The same operating-system command authority can modify programs and controller behavior across every reachable affected robot, without exposing a firmware-signing key.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Cross-domain reusable bridge (one exploit to many controllers).

Model inference
Reuse scaleSR 3
Portable product-class technique

Shared software version and exploit portability deployment-wide.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

The injection request can be scripted across reachable affected controllers without a physical visit to each robot cell.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Recovery requires patching and segmenting every controller across the deployment (fleet action).

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandEMERGENCY
  2. No adjustment

    The EMERGENCY base band remains final because no separate cap or systemic uplift applies. The same operating-system command authority can modify programs and controller behavior across every reachable affected robot, without exposing a firmware-signing key.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:4/EX:4/PH:3/DP:3/AT:3/CH:4/SR:3/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Authority · Co-dominant path

Account authority

The attacker gains operating-system command authority over the controller and can modify robot programs and configuration, but not the vendor signing root.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    Unauthenticated network surface.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    Controller takeover is a strong pivot into both safety and fleet paths.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Administrative or command authority

    The attacker gains operating-system command authority over the controller and can modify robot programs and configuration, but not the vendor signing root.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Account authority

    The attacker gains operating-system command authority over the controller and can modify robot programs and configuration, but not the vendor signing root.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Software patch plus port and network restriction.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

Unauthenticated network surface.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Single low-complexity injection.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Availability and workflow disruption of the controller at this terminal (severe actuation harm scored separately).

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Exposes program logic, process data, and connected I and O state.

Model inference
AuthorityAT 3
Administrative or command authority

The attacker gains operating-system command authority over the controller and can modify robot programs and configuration, but not the vendor signing root.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

Controller takeover is a strong pivot into both safety and fleet paths.

Model inference
Reuse scaleSR 2
Repeatable method

Version-shared reachability.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Remotely scriptable across reachable targets.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Software patch plus port and network restriction.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandEMERGENCY
  2. No adjustment

    The EMERGENCY base band remains final because no separate cap or systemic uplift applies. The attacker gains operating-system command authority over the controller and can modify robot programs and configuration, but not the vendor signing root.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:3/CH:3/SR:2/SX:4/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the safety transition before acting on the band.

Triage beyond the first device: verify whether the reusable condition, propagation mechanism, and recovery dependency actually exist across the deployment.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 9.8 CRITICALCNA via NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Universal Robots PolyScope 5 Dashboard Server OS command injection (CVE-2026-8153) at EMERGENCY — the worst of 3 risk paths (safety, authority). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

Universal Robots PolyScope 5 Dashboard Server OS command injection (CVE-2026-8153). Reported attack vector: Network.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYEMERGENCY

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:3/CH:4/SR:2/SX:4/OR:2/EV:2/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=CRITICAL · AT=CRITICAL → base EMERGENCY · uplift fleet-reachable authority → assessed EMERGENCY.

Unauthenticated network-reachable OS command injection (AV:N/AC:L/PR:N) on the PolyScope controller that drives a collaborative arm operating near humans. RE:4 default-exposed network service; EC:4 single low-complexity request, no auth. AT:3 arbitrary OS command execution = service/admin-level control over the controller and its motion programs (not a signing/OTA trust root). PH:4 OS-level control can alter motion of an industrial cobot designed to work near people -> credible injury/dangerous actuation. DP:3 controller exposes program logic and operational state. CH:4 crosses network->controller->physical/safety boundaries and bridges into actuation. SX:4 scriptable across every reachable controller of same version; SR:2 same software version reuse, not a shared secret/key. OR:2 software patch (5.25.1) plus segmentation; no hardware recall. EV:2 vendor+CISA report-backed, no public weaponized PoC. Physical effect inferred from arm control, so EV stays modelled/report-backed.

FLEET_CONTROL_PLANEEMERGENCY

CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:4/EX:4/PH:4/DP:3/AT:3/CH:4/SR:3/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=CRITICAL · AT=CRITICAL → base EMERGENCY · uplift fleet-reachable authority → assessed EMERGENCY.

Cobots deploy in fleets across cells/lines on flat factory networks; an unauthenticated network RCE is scriptable and self-propagatable to every reachable controller of the same PolyScope version. RE:4 network-default-exposed; EC:4 trivial reproducible exploitation. AT:3 controller-level command authority replicated fleet-wide (not OTA/signing root, so not 4). PH:3 fleet-wide motion influence reduces safety margins across many cells but per-cell severe harm is captured in the safety path. DP:3 process/program data across the fleet. CH:4 cross-domain reusable bridge (one exploit -> many controllers). SR:3 shared software version/exploit portability deployment-wide; SX:4 fleet-scale remote execution without per-device physical access. OR:3 recovery requires patching/segmenting every controller across the deployment (fleet action). EV:2 report-backed advisory, no field-confirmed worm.

ACCOUNT_AUTHORITYEMERGENCY

CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:3/CH:3/SR:2/SX:4/OR:2/EV:2/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=CRITICAL · AT=CRITICAL → base EMERGENCY · uplift fleet-reachable authority → assessed EMERGENCY.

Direct terminal of the flaw itself: full compromise (C:H/I:H/A:H) of the controller OS with no credentials. RE:4 unauthenticated network surface; EC:4 single low-complexity injection. AT:3 attacker gains arbitrary OS command authority over the controller (service/admin-level), able to modify config and programs; not a signing/identity root so not 4. PH:2 availability/workflow disruption of the controller at this terminal (severe actuation harm scored separately). DP:3 exposes program logic, process data, and connected I/O state. CH:3 controller takeover is a strong pivot into both safety and fleet paths. SR:2 version-shared reachability; SX:4 remotely scriptable across reachable targets. OR:2 software patch plus port/network restriction. EV:2 vendor and CISA confirmed, report-backed.

Published baseline

  • v3.1 9.8 CRITICAL — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — CNA via NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0027 (“Universal Robots PolyScope 5 Dashboard Server OS command injection (CVE-2026-8153)”), paths.cfse.ai/CPATH-2026-0027 (published 2026-06-03).