Critical Vulnerability Exposes Industrial Robot Fleets to Hacking
Vulnerability: Critical command injection flaw (CVE-2026-8153) in Universal Robots' cobot OS enables unauthenticated RCE via Dashboard Server interface.
Deep Analysis and Expert Commentary
The attack path begins with network access to the Dashboard Server port (typically TCP 29999), where crafted commands bypass input validation. Unlike traditional industrial robots, cobots' Ethernet-enabled control boxes create additional entry points, particularly when connected to flat OT networks using legacy protocols like MODBUS. Compromise escalates from single cobot manipulation (posing physical safety risks) to fleet-wide control due to lack of network segmentation. Mitigation requires immediate patching, disabling Dashboard Server if unused, and implementing microsegmentation between cobots and other OT assets. Asset owners should audit all cobot network connections, as many installations use these devices in bridged network topologies for legacy integration.
Action Items
- Patch all Universal Robots systems to PolyScope 5.25.1 immediately
- Disable Dashboard Server interface if not required for operations
- Implement network segmentation between cobots and other OT equipment
Original Article Brief Intro
SecurityWeek · 2026-05-19 · Vulnerability: Critical command injection flaw (CVE-2026-8153) in Universal Robots' cobot OS enables unauthenticated RCE via Dashboard Server interface.
Related Terms and Notes
CVE IDs
- CVE-2026-8153 — Critical OS command injection vulnerability in Universal Robots' PolyScope 5 Dashboard Server (CVSS 9.8)
Malware Families
- cobots — Collaborative industrial robots designed to work alongside human operators in shared workspaces
Techniques / TTPs
- RCE
Context Notes
- cobots
- ICS
- Industrial robots
- OT networks
- OT_security
- PolyScope
- Remote Code Execution