Junglewise Threat Intelligence

CVE-2026-16675: Rockwell Automation FactoryTalk Activation Manager privilege escalation in installer

CVE-2026-16675 · Severity: info · CVSS 8.5 · Published 2026-09-01

Vendors: Rockwell Automation.

Executive brief

FactoryTalk Activation Manager is a licensing and activation tool for Rockwell Automation industrial products. A privilege escalation flaw in the installer allows authenticated Windows users to hijack system processes running with administrative privileges during installation or repair, gaining complete control over the system and all its data.

Technical details

The vulnerability is a privilege escalation in the custom installer actions of FactoryTalk Activation Manager, stemming from visible console windows spawned with SYSTEM-level privileges during installation or repair operations. An authenticated attacker with local Windows credentials can hijack these windows to obtain a SYSTEM-level command prompt. The attack requires local system access and an active installation or repair operation, but no special privileges beforehand. Successful exploitation grants full control over all files, processes, and system resources. Patched versions are available; v5.03 and later correct this issue.

Affected products

  • Rockwell Automation FactoryTalk Activation Manager 5.02 and below

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Corrected in version 5.03

References