mediumOther

Rockwell Automation FactoryTalk DataMosaix Stored Cross-Site Scripting Vulnerability (CVE-2026-9292)

First seen Jul 18, 2026 · Updated Jul 18, 2026 · CVSS 6.1

ICSSCADACISA-advisoryXSSweb-vulnerabilitycritical-manufacturingrockwell-automation

A stored cross-site scripting (XSS) vulnerability affects Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier, allowing an authenticated high-privilege attacker to inject persistent malicious scripts via the Workflows configuration. Successful exploitation could lead to account takeover, credential theft, or redirection of other users to malicious sites when they access the affected page. No public exploitation has been reported to date.

Technical Analysis

CVE-2026-9292 is a CWE-79 stored XSS vulnerability caused by improper neutralization of user-supplied input in the Workflows configuration of FactoryTalk DataMosaix Private Cloud. An authenticated attacker with high privileges can persist malicious JavaScript that executes in the browser context of other users viewing the affected page, enabling session hijacking, credential theft, or redirection to attacker-controlled infrastructure. The vulnerability scores 6.1 (Medium) under CVSS v3.1 (AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N) but 8.4 (High) under CVSS v4.0, reflecting differing weight given to privilege requirements and user interaction. This is a traditional web application vulnerability in an industrial data platform rather than a network-level RCE; exploitation requires authenticated access and victim interaction, limiting mass exploitation potential. If DataMosaix or its workflow interfaces are integrated with AI agent orchestration or automated data pipelines (e.g., agents consuming or triggering workflows via this web UI), a compromised session token or stolen credential resulting from this XSS could be leveraged to manipulate agent-driven data workflows or exfiltrate API keys/credentials used by connected automation tooling, so organizations running agentic systems atop this platform should treat session and credential hygiene as a priority.

Affected Systems

Rockwell Automation FactoryTalk DataMosaix Private Cloud, versions 8.02 and earlier. Fixed in version 8.03 and later.

Indicators of Compromise

  • No known IOCs associated with this vulnerability; no public exploitation reported at this time.

Remediation Steps

  1. 1

    Upgrade DataMosaix Private Cloud

    Update to FactoryTalk DataMosaix Private Cloud version 8.03 or later, which contains the vendor fix for CVE-2026-9292.

  2. 2

    Apply Rockwell Security Best Practices

    If immediate upgrade is not possible, implement Rockwell Automation's published security best practices (referenced in support knowledge base article a_id/1085012) to reduce exploitation risk.

  3. 3

    Restrict Network Exposure

    Ensure control system devices and DataMosaix instances are not accessible from the internet; place them behind firewalls and segment from business networks.

  4. 4

    Enforce Least Privilege for Workflow Configuration

    Limit high-privilege accounts capable of modifying Workflows configuration, and monitor/audit changes to reduce the attack surface for stored XSS injection.

  5. 5

    Use Secure Remote Access

    If remote access to DataMosaix is required, use updated VPN solutions rather than direct exposure, and monitor VPN endpoints for compromise.

  6. 6

    Review Rockwell Advisory SD1787

    Consult Rockwell Automation Security Advisory SD1787 for detailed mitigation guidance specific to this vulnerability.

CVE / Advisory IDs

CVE-2026-9292

Industries Most Exposed

Critical ManufacturingInformation Technology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.