CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Rockwell Automation FactoryTalk DataMosaix

criticalCVE-2026-9292
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server. The following versions of Rockwell Automation FactoryTalk DataMosaix are affected: DataMosaix Private Cloud <=8.02 (CVE-2026-9292) CVSS Vendor Equipment Vulnerabilities v3 6.1 Rockwell Automation Rockwell Automation FactoryTalk DataMosaix Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9292 A Stored Cross-Site Scripting security issue exists within FactoryTalk DataMosaix Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website. View CVE Details Affected Products Rockwell Automation FactoryTalk DataMosaix Vendor: Rockwell Automation Product Version: Rockwell Automation DataMosaix Private Cloud: <=8.02 Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users to upgrade to the following: DataMosaix Private Cloud versions 8.03 or later. Mitigation Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation For more information, see Rockwell Automation Sec

CSIRTS triage

What
A stored cross-site scripting vulnerability exists in FactoryTalk DataMosaix.
Who is affected
Users of FactoryTalk DataMosaix Private Cloud version 8.02 or earlier.
Urgency
Remediation is critical due to the potential for script injection.
Action
Users should update to a version later than 8.02.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch FactoryTalk DataMosaix

Get an email when a new FactoryTalk DataMosaix advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-07-16
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-09

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-9292coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Rockwell Automation FactoryTalk

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Cybersecurity Advisories