Rockwell Automation FactoryTalk DataMosaix Stored Cross-Site Scripting Vulnerability (CVE-2026-9292)
mediumOtherA stored cross-site scripting (XSS) vulnerability affects Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier, allowing an authenticated high-privilege attacker to inject persistent malicious scripts via the Workflows configuration. Successful exploitation could lead to account takeover, credential theft, or redirection of other users to malicious sites when they access the affected page. No public exploitation has been reported to date.
Updated Jul 18, 2026 · CVSS 6.1