Junglewise Threat Intelligence

CVE-2026-19471: Rockwell Automation ArmorStart LT stored cross-site scripting

CVE-2026-19471 · Severity: info · CVSS 7.3 · Published 2026-09-01

Vendors: Rockwell Automation.

Executive brief

Rockwell Automation's ArmorStart LT is a distributed motor controller used in industrial automation systems. The product contains a stored cross-site scripting (XSS) vulnerability that allows an attacker to inject malicious scripts through unsanitized user input. When other users access the affected pages, these scripts execute in their browsers, potentially leading to credential theft, session hijacking, or unauthorized actions within the control system.

Technical details

CVE-2026-19471 is a stored cross-site scripting vulnerability in ArmorStart LT caused by improper sanitization of user input before storage on the server (CWE-79). The vulnerability affects firmware versions v2.001 and below. An attacker with network access to the embedded web interface can inject malicious JavaScript that persists on the server and executes in the browser of any user who subsequently accesses the affected page. The web-based interface is network-reachable, though specific authentication requirements are not detailed. A patch is available in firmware version v2.002.

Affected products

  • Rockwell Automation ArmorStart LT v2.001 and below

Timeline

  • 2026-09-01: disclosed

References

Related threats