Impact
The vulnerability allows a threat actor who already holds basic user privileges to gain unauthorized access to users’ projects. If exploited the actor can modify or delete a project, resulting in loss of data integrity and potential leakage of sensitive information. This flaw is classified as CWE‑287, an improper authentication weakness.
Affected Systems
Rockwell Automation’s DataMosaix Private Cloud 7.07 is affected. The product exposes a flaw in its web‑based project management interface that does not enforce strict access controls for modify and delete operations.
Risk and Exploitability
The CVSS vector assigns a score of 7.6, indicating a high severity risk. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified. The advisory does not list it in the CISA KEV catalog. The attack requires an authenticated user with basic rights and likely proceeds through the standard project editing API or UI, with no additional pre‑conditions revealed in the public description.
OpenCVE Enrichment