Description
A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authentication. If exploited, a threat actor could view customer data.
Published: 2026-09-01
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

This vulnerability occurs when source code contains hard‑coded URLs that expose JSON data files. The files are reachable without authentication, enabling an attacker to view customer information. The exposure can compromise the confidentiality of data stored in the platform, and the potential impact is limited to information disclosure without affecting integrity or availability.

Affected Systems

The affected product is Rockwell Automation’s DataEdgePlatform DataMosaix Private Cloud, specifically version 7.07. The flaw exists in all installations of this version that deploy the exposed JSON files.

Risk and Exploitability

The CVSS score of 8.7 classifies it as a high‑severity flaw. No EPSS score is available, so the exploitation likelihood cannot be quantified, and it is not yet listed as a known exploited vulnerability. The attack vector is inferred to be unauthenticated network access to the exposed JSON endpoints, which can be performed from any host able to reach the server. Because no authentication is required, the risk is significant for systems exposed to the Internet or to untrusted networks.

Generated by OpenCVE AI on September 1, 2026 at 23:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest update of DataEdgePlatform DataMosaix Private Cloud when it becomes available and confirms removal or protection of the hard‑coded JSON links.
  • If a patch is not yet available, restrict network access to the JSON endpoints by using firewalls or placing the service behind an authentication gateway so that only authorized users can retrieve the files.
  • As an immediate workaround, manually delete or rename the exposed JSON files from the server configuration to prevent accidental disclosure.
  • Review and secure all configuration files to eliminate hard‑coded links or credentials in future releases.

Generated by OpenCVE AI on September 1, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation dataedgeplatform Datamosaix Private Cloud
Vendors & Products Rockwellautomation
Rockwellautomation dataedgeplatform Datamosaix Private Cloud

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authentication. If exploited, a threat actor could view customer data.
Title DataEdgePlatform DataMosaix™ Private Cloud
First Time appeared Rockwell Automation
Rockwell Automation dataedgeplatform Datamosaix Private Cloud
Weaknesses CWE-798
CPEs cpe:2.3:a:rockwell_automation:dataedgeplatform_datamosaix_private_cloud:_7.07:*:*:*:*:*:*:*
Vendors & Products Rockwell Automation
Rockwell Automation dataedgeplatform Datamosaix Private Cloud
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Rockwell Automation Dataedgeplatform Datamosaix Private Cloud
Rockwellautomation Dataedgeplatform Datamosaix Private Cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-09-01T17:50:39.723Z

Reserved: 2024-08-19T18:14:00.281Z

Link: CVE-2024-7952

cve-icon Vulnrichment

Updated: 2026-09-01T17:50:19.134Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T18:17:38.110

Modified: 2026-09-01T20:50:01.960

Link: CVE-2024-7952

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:27:38Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials