Junglewise Threat Intelligence

CVE-2024-7956: Rockwell Automation DataMosaix Private Cloud incorrect authorization

CVE-2024-7956 · Severity: info · CVSS 8.1 · Published 2026-09-02

Technologies: Rockwell Automation DataMosaix Private Cloud. Vendors: Rockwell Automation.

Executive brief

DataMosaix Private Cloud is an industrial automation and data management platform used by enterprises to manage production data and projects. A vulnerability allows authenticated users with basic privileges to access and modify other users' projects without proper authorization, potentially exposing sensitive operational data and enabling sabotage of critical industrial projects.

Technical details

CVE-2024-7956 is an incorrect authorization vulnerability in Rockwell Automation DataMosaix Private Cloud affecting versions ≤7.07, fixed in v7.09. The vulnerability allows an authenticated attacker with basic user privileges to gain unauthorized access to other users' projects through missing authorization checks. The attacker can view, modify, and delete projects they do not own, exploiting an unauthenticated or inadequately validated access control mechanism. Network reachability and valid user credentials are required; no user interaction is necessary. The vulnerability has been patched in version 7.09 and is not known to be exploited in the wild.

Affected products

  • Rockwell Automation DataMosaix Private Cloud ≤7.07

Timeline

  • 2024-10-04: disclosed: Published in Rockwell Automation Security Advisory SD1702
  • 2024-10-04: patched: Corrected in DataMosaix Private Cloud v7.09

References

Related threats