Junglewise Threat Intelligence

CVE-2026-9292: Rockwell Automation FactoryTalk DataMosaix Private Cloud XSS in Workflows

CVE-2026-9292 · Severity: info · CVSS 8.4 · Published 2026-07-14

Vendors: Rockwell Automation.

Executive brief

Rockwell Automation's FactoryTalk DataMosaix Private Cloud, an industrial data operations platform, is affected by a security flaw in its workflow configuration. An attacker with high-level access can plant malicious scripts that remain on the server and execute when other users view the affected pages. This could lead to unauthorized access to user accounts, theft of login credentials, or redirection to dangerous websites, potentially disrupting industrial data management.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Rockwell Automation FactoryTalk DataMosaix Private Cloud due to improper neutralization of user-supplied input within the Workflows configuration (CWE-79). An authenticated attacker with high privileges can inject malicious JavaScript that is permanently stored on the server. The attack requires a victim to view the compromised configuration page (user interaction). Successful exploitation can result in the execution of arbitrary scripts in the context of the victim's browser session, enabling session hijacking, credential theft, or unauthorized actions. The vulnerability is addressed in version 8.03.

Affected products

  • Rockwell Automation FactoryTalk DataMosaix Private Cloud 8.02 and below

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory
  • 2026-07-14: patched: Fixed in version 8.03

References