Description
Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page.
Published: 2026-09-01
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

ArmorStart® LT stores user supplied input on the server without proper sanitization, leading to stored cross‑site scripting. An attacker can embed malicious JavaScript that executes in the browsers of any user who views the affected page, potentially allowing session hijacking, credential theft, or arbitrary code execution in the victim’s context. The weakness is a classic reflected input handling flaw, classified as CWE‑79.

Affected Systems

The affected product is Rockwell Automation’s ArmorStart® LT, particularly versions 2.001 and earlier.

Risk and Exploitability

The vulnerability has a CVSS score of 6.9, indicating moderate severity. EPSS information is currently unavailable, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector requires an attacker to submit malicious input that is stored on the server, which generally implies the attacker must have legitimate user or privileged access to the system. From the available data, no exploitation conditions beyond this are identified.

Generated by OpenCVE AI on September 1, 2026 at 15:58 UTC.

Remediation

Vendor Solution

Upgrade to version  v2.002 https://compatibility.rockwellautomation.com/Pages/Downloads.aspx  or later.


OpenCVE Recommended Actions

  • Apply the vendor‑provided patch that upgrades ArmorStart® LT to version 2.002 or newer.
  • Remove or audit web pages and forms that accept unvalidated input, ensuring that JavaScript tags are stripped or encoded.
  • Verify that database entries containing user input are properly escaped before rendering, enforcing server‑side sanitization.

Generated by OpenCVE AI on September 1, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation armorstart Lt
Vendors & Products Rockwellautomation
Rockwellautomation armorstart Lt

Tue, 01 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page.
Title Rockwell Automation ArmorStart® LT Stored Cross-site scripting
First Time appeared Rockwell Automation
Rockwell Automation armorstart Lt
Weaknesses CWE-79
CPEs cpe:2.3:a:rockwell_automation:armorstart_lt:v2.001_and_below:*:*:*:*:*:*:*
Vendors & Products Rockwell Automation
Rockwell Automation armorstart Lt
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Rockwell Automation Armorstart Lt
Rockwellautomation Armorstart Lt
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-09-01T15:40:53.080Z

Reserved: 2026-08-10T14:37:12.656Z

Link: CVE-2026-19471

cve-icon Vulnrichment

Updated: 2026-09-01T15:40:49.948Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T13:18:12.707

Modified: 2026-09-01T21:03:04.987

Link: CVE-2026-19471

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T16:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')