Impact
A flaw allows an attacker to create a new project and assume the administrator role for that project. Once the role is acquired, the attacker can create, modify, or delete all aspects of the project, granting extensive control over the private cloud environment.
Affected Systems
The vulnerability affects Rockwell Automation's DataEdgePlatform DataMosaix™ Private Cloud, version 7.07, and has been identified for all installations of this product variant.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score is not available, but the lack of a KEV listing suggests no widespread exploitation has been reported yet. The attack vector is inferred to be local or network‑based application access, as the flaw requires the ability to create a project through the platform's interface. Once accessed, an attacker can gain elevated privileges within the affected system.
OpenCVE Enrichment