news.mlab.sh
Back to the feed
vulnerability

Rockwell Automation FactoryTalk DataMosaix

Critical
Summary

Rockwell Automation has issued a security advisory regarding a critical vulnerability (CVE-2026-9292) in its FactoryTalk DataMosaix Private Cloud software. An authenticated attacker can inject malicious scripts that are permanently stored on the server, potentially leading to account takeover, credential theft, or redirection to malicious websites. The vulnerability stems from improper input neutralization within the Workflows configuration and affects versions 8.02 and earlier.

Rockwell Automation has identified and announced a critical security vulnerability in its FactoryTalk DataMosaix Private Cloud software. The vulnerability, identified as CVE-2026-9292, is a Stored Cross-Site Scripting (XSS) issue. This means an authenticated attacker can inject malicious scripts into the system that are then permanently stored on the server. When other users access the affected page, these injected scripts will execute, potentially enabling account takeover, credential theft, or redirection to a malicious website. The vulnerability originates from improper neutralization of user-supplied input within the Workflows configuration.

This issue affects Rockwell Automation FactoryTalk DataMosaix and Rockwell Automation specifically.

Rockwell Automation recommends that users upgrade to version 8.03 or later to remediate this vulnerability. For organizations unable to upgrade, Rockwell Automation advises implementing their security best practices, available at https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.

CISA recommends organizations take defensive measures to minimize the risk of exploitation, including minimizing network exposure for control system devices, locating control systems behind firewalls, and utilizing more secure remote access methods like VPNs (updated to the latest version). Organizations should also perform impact analysis and risk assessments.

Rockwell Automation reported this vulnerability to CISA. No public exploitation specifically targeting this vulnerability has been reported at the time of this advisory.

Read the full article at CISA Advisories