Description
A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website.
Published: 2026-07-14
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stored cross‑site scripting flaw in FactoryTalk DataMosaix Private Cloud allows an authenticated user with high privileges to inject malicious JavaScript into workflow configuration fields. The unneutralized input is permanently saved on the server, so any subsequent user who views the affected page will have the script executed in their browser. This can lead to session hijacking, credential theft, or forced redirection to attacker‑controlled sites.

Affected Systems

All installations of Rockwell Automation FactoryTalk DataMosaix Private Cloud running versions earlier than 8.03 are potentially affected, as the remediation provided by the vendor recommends upgrading to 8.03 or later.

Risk and Exploitability

The CVSS score of 8.4 classifies the vulnerability as high severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Likely exploitation requires an authenticated account with elevated privileges to submit the malicious payload through the workflow interface; after injection, the attack remains dormant until another authorized user accesses the page, at which point the stored script runs in that user’s browser.

Generated by OpenCVE AI on July 31, 2026 at 10:16 UTC.

Remediation

Vendor Solution

Upgrade to version  8.03 or later.


OpenCVE Recommended Actions

  • Upgrade FactoryTalk DataMosaix Private Cloud to version 8.03 or later
  • Restrict privileged user accounts and enforce least privilege for workflow configuration management
  • Review existing workflow configurations and disable or sanitize custom script fields before deployment

Generated by OpenCVE AI on July 31, 2026 at 10:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website.
Title Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-07-14T15:53:41.359Z

Reserved: 2026-05-22T17:18:30.808Z

Link: CVE-2026-9292

cve-icon Vulnrichment

Updated: 2026-07-14T15:53:38.413Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')