Junglewise Threat Intelligence

CVE-2024-7953: Rockwell Automation DataMosaix Private Cloud privilege escalation

CVE-2024-7953 · Severity: info · CVSS 8.8 · Published 2026-09-01

Technologies: Rockwell Automation DataMosaix Private Cloud. Vendors: Rockwell Automation.

Executive brief

DataMosaix Private Cloud is an industrial data analytics platform used to manage projects and customer data in manufacturing environments. This vulnerability allows an authenticated user to create a project and gain administrative privileges over it, potentially enabling them to access, modify, or delete projects belonging to other users. An attacker with basic user access could expand their privileges and compromise business-critical production data.

Technical details

CVE-2024-7953 is a missing authorization vulnerability in DataMosaix Private Cloud versions ≤7.07 that allows an authenticated user to escalate privileges and create projects with administrator access. The vulnerability requires low privileges (PR:L) and network reachability but no user interaction. An attacker can leverage improper access controls to create, modify, and delete projects, including those belonging to other users. The issue is corrected in version 7.09. This is one of three related authorization flaws affecting the same product alongside CVE-2024-7952 (unauthenticated data exposure) and CVE-2024-7956 (project access bypass).

Affected products

  • Rockwell Automation DataMosaix Private Cloud ≤7.07

Timeline

  • 2024-10-04: disclosed
  • 2024-10-04: patched: Corrected in version 7.09

References

Related threats