Executive brief
Rockwell Automation FactoryTalk Services Platform, which manages communication and data exchange between industrial automation components, contains a security flaw in how it handles user logins via Okta. An attacker with low-level access to the system can bypass security checks to impersonate any other user, including administrators. This could allow an unauthorized person to change critical system configurations or grant themselves access to other connected industrial systems.
Technical details
A weak authentication vulnerability (CWE-1390) exists in FactoryTalk Services Platform (FTSP) v6.60 during Okta Web Authentication. The application fails to verify that the JSON Web Token (JWT) algorithm is restricted to RSA, allowing an attacker to modify the header to use the 'none' algorithm. By crafting a forged token with no signature, an authenticated user with low privileges can bypass signature validation. This enables impersonation of any authorized user on the FTSP server, providing a path to unauthorized system configuration changes and privilege escalation across protected systems. A patch (RAID 1158263) or the February 2026 Patch Roll-up is available to resolve this issue.
Affected products
- Rockwell Automation FactoryTalk Services Platform (FTSP) 6.60
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory
- 2026-02-01: patched: February 2026 Patch Roll-up contains the fix.