Rockwell Automation FactoryTalk DataMosaix
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server. The following versions of Rockwell Automation FactoryTalk DataMosaix are affected: DataMosaix Private Cloud <=8.02 (CVE-2026-9292) CVSS Vendor Equipment Vulnerabilities v3 6.1 Rockwell Automation Rockwell Automation FactoryTalk DataMosaix Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9292 A Stored Cross-Site Scripting security issue exists within FactoryTalk DataMosaix Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website. View CVE Details Affected Products Rockwell Automation FactoryTalk DataMosaix Vendor: Rockwell Automation Product Version: Rockwell Automation DataMosaix Private Cloud: <=8.02 Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users to upgrade to the following: DataMosaix Private Cloud versions 8.03 or later. Mitigation Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation For more information, see Rockwell Automation Sec
CSIRTS triage
- What
- A stored cross-site scripting vulnerability exists in FactoryTalk DataMosaix.
- Who is affected
- Users of FactoryTalk DataMosaix Private Cloud version 8.02 or earlier.
- Urgency
- Remediation is critical due to the potential for script injection.
- Action
- Users should update to a version later than 8.02.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FactoryTalk DataMosaix
Get an email when a new FactoryTalk DataMosaix advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-09
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-92920.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-9292 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Rockwell Automation FactoryTalk
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalRockwell Automation FactoryTalk Services Platformcisa · 2026-07-21
- medium[NEW] [medium] Rockwell Automation FactoryTalk Services Platform and DataMosaix Private Cloud: Multiple vulner…cert-bund · 2026-07-15
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalMZ Automation GmbH libiec618502026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30