Junglewise Threat Intelligence

CVE-2025-14272: Rockwell Automation FactoryTalk Analytics PavilionX improper API authorization

CVE-2025-14272 · Severity: info · CVSS 8.3 · Published 2026-06-16

Vendors: Rockwell Automation.

Executive brief

Rockwell Automation FactoryTalk Analytics PavilionX, a platform used for industrial process optimization and analytics, contains a security flaw in its programming interfaces. An unauthorized person could exploit this to perform administrative tasks, such as managing user accounts and roles. This could lead to unauthorized access to industrial data or disruption of manufacturing process controls.

Technical details

A missing authorization vulnerability (CWE-862) exists in the API endpoints of Rockwell Automation FactoryTalk Analytics PavilionX version 7.00. The flaw allows an unauthenticated or unauthorized attacker to bypass security checks and execute privileged operations. Specifically, an attacker can perform administrative tasks such as user and role management. The vulnerability is exploitable over the network, though the CVSS 4.0 score indicates high access complexity. Rockwell Automation has released version 7.01 to address this issue.

Affected products

  • Rockwell Automation FactoryTalk Analytics PavilionX 7.00

Timeline

  • 2026-06-16: disclosed: Initial advisory release by Rockwell Automation
  • 2026-06-16: patched: Fixed in version 7.01

References