Rockwell Automation FactoryTalk DataMosaix Stored Cross-Site Scripting Vulnerability (CVE-2026-9292)
First seen Jul 18, 2026 · Updated Jul 18, 2026 · CVSS 6.1
A stored cross-site scripting (XSS) vulnerability affects Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier, allowing an authenticated high-privilege attacker to inject persistent malicious scripts via the Workflows configuration. Successful exploitation could lead to account takeover, credential theft, or redirection of other users to malicious sites when they access the affected page. No public exploitation has been reported to date.
Technical Analysis
CVE-2026-9292 is a CWE-79 stored XSS vulnerability caused by improper neutralization of user-supplied input in the Workflows configuration of FactoryTalk DataMosaix Private Cloud. An authenticated attacker with high privileges can persist malicious JavaScript that executes in the browser context of other users viewing the affected page, enabling session hijacking, credential theft, or redirection to attacker-controlled infrastructure. The vulnerability scores 6.1 (Medium) under CVSS v3.1 (AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N) but 8.4 (High) under CVSS v4.0, reflecting differing weight given to privilege requirements and user interaction. This is a traditional web application vulnerability in an industrial data platform rather than a network-level RCE; exploitation requires authenticated access and victim interaction, limiting mass exploitation potential. If DataMosaix or its workflow interfaces are integrated with AI agent orchestration or automated data pipelines (e.g., agents consuming or triggering workflows via this web UI), a compromised session token or stolen credential resulting from this XSS could be leveraged to manipulate agent-driven data workflows or exfiltrate API keys/credentials used by connected automation tooling, so organizations running agentic systems atop this platform should treat session and credential hygiene as a priority.
Affected Systems
Rockwell Automation FactoryTalk DataMosaix Private Cloud, versions 8.02 and earlier. Fixed in version 8.03 and later.
Indicators of Compromise
- No known IOCs associated with this vulnerability; no public exploitation reported at this time.
Remediation Steps
- 1
Upgrade DataMosaix Private Cloud
Update to FactoryTalk DataMosaix Private Cloud version 8.03 or later, which contains the vendor fix for CVE-2026-9292.
- 2
Apply Rockwell Security Best Practices
If immediate upgrade is not possible, implement Rockwell Automation's published security best practices (referenced in support knowledge base article a_id/1085012) to reduce exploitation risk.
- 3
Restrict Network Exposure
Ensure control system devices and DataMosaix instances are not accessible from the internet; place them behind firewalls and segment from business networks.
- 4
Enforce Least Privilege for Workflow Configuration
Limit high-privilege accounts capable of modifying Workflows configuration, and monitor/audit changes to reduce the attack surface for stored XSS injection.
- 5
Use Secure Remote Access
If remote access to DataMosaix is required, use updated VPN solutions rather than direct exposure, and monitor VPN endpoints for compromise.
- 6
Review Rockwell Advisory SD1787
Consult Rockwell Automation Security Advisory SD1787 for detailed mitigation guidance specific to this vulnerability.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.