CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-9292

criticalcovered by 3 sourcesfirst seen 2026-07-14
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server. The following versions of Rockwell Automation FactoryTalk DataMosaix are affected: DataMosaix Private Cloud <=8.02 (CVE-2026-9292) CVSS Vendor Equipment Vulnerabilities v3 6.1 Rockwell Automation Rockwell Automation FactoryTalk DataMosaix Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9292 A Stored Cross-Site Scripting security issue exists within FactoryTalk DataMosaix Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website. View CVE Details Affected Products Rockwell Automation FactoryTalk DataMosaix Vendor: Rockwell Automation Product Version: Rockwell Automation DataMosaix Private Cloud: <=8.02 Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users to upgrade to the following: DataMosaix Private Cloud versions 8.03 or later. Mitigation Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation For more information, see Rockwell Automation Sec

CSIRTS triage

What
A stored cross-site scripting vulnerability exists in FactoryTalk DataMosaix.
Who is affected
Users of FactoryTalk DataMosaix Private Cloud version 8.02 or earlier.
Urgency
Remediation is critical due to the potential for script injection.
Action
Users should update to a version later than 8.02.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-9292

Get an email if CVE-2026-9292 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-9292

CVE.org record

Embed the live status

CVE-2026-9292 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-9292 status](https://www.csirts.com/badge/CVE-2026-9292)](https://www.csirts.com/cve/CVE-2026-9292)