mediumOther

Rockwell Automation OTTO Fleet Manager Weak Password Hashing Vulnerability (CVE-2026-75112)

First seen Aug 28, 2026 · Updated Aug 28, 2026 · CVSS 6.8

icsotrockwell-automationpassword-hashingbcryptcwe-916cisa-advisorycritical-manufacturingtransportation

Rockwell Automation OTTO Fleet Manager versions up to V2.36.2 use a bcrypt implementation with an insufficient work factor, weakening stored password hashes against offline brute-force attacks. Exploitation requires an attacker to first obtain an unencrypted system backup, after which weakly hashed credentials could be cracked more easily. Rockwell has released version 2.36.3 to remediate the issue, along with guidance to enable encrypted system backups.

Technical Analysis

CVE-2026-75112 (CWE-916: Use of Password Hash With Insufficient Computational Effort) affects Rockwell Automation OTTO Fleet Manager versions <=V2.36.2, which is used to manage fleets of autonomous mobile robots in industrial and logistics environments. The vulnerability arises from a bcrypt work factor set too low, reducing the computational cost of offline brute-force attacks against stored password hashes; exploitation requires adjacent network access (AV:A) and low privileges, and is contingent on an attacker first acquiring an unencrypted system backup containing the hash database. CVSS v3.1 scores this 6.8 (Medium) with high confidentiality impact and no integrity/availability impact, and no public exploitation has been observed. While this is an OT/robotics fleet management product rather than an AI agent framework component, organizations that integrate OTTO fleet data or credentials into AI-driven robotics orchestration, RAG-based operational dashboards, or agentic automation pipelines should treat any compromised credentials from this system as a potential pivot point for lateral movement into agent-connected infrastructure.

Affected Systems

Rockwell Automation OTTO Fleet Manager versions <=V2.36.2 (fixed in V2.36.3); deployments in Critical Manufacturing and Transportation Systems sectors worldwide.

Indicators of Compromise

  • No known IOCs; this is a vulnerability disclosure, not an active exploitation campaign.

Remediation Steps

  1. 1

    Upgrade OTTO Fleet Manager

    Update to version 2.36.3 or later, which addresses the insufficient bcrypt work factor issue.

  2. 2

    Enable Encrypted System Backups

    Follow Rockwell Automation advisory SD1791 to enable encrypted backups, preventing exposure of weakly hashed credentials if a backup is accessed by an attacker.

  3. 3

    Restrict Network Exposure

    Ensure OTTO Fleet Manager and related control system devices are not internet-accessible; place them behind firewalls and segment from business networks.

  4. 4

    Use Secure Remote Access

    If remote access is required, use up-to-date VPN solutions and apply CISA's defense-in-depth recommendations for ICS environments.

  5. 5

    Protect Backup Files

    Restrict access controls and storage security for system backups to prevent unauthorized retrieval of password hash data.

  6. 6

    Rotate Credentials

    After upgrading, rotate all user passwords managed by OTTO Fleet Manager to ensure any previously weakly-hashed credentials are invalidated.

CVE / Advisory IDs

CVE-2026-75112

Industries Most Exposed

Critical ManufacturingTransportation Systems

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.