PT-2026-58084 · Rockwell Automation · Factorytalk® Datamosaix™ Private Cloud

CVE-2026-9292

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions FactoryTalk DataMosaix Private Cloud (affected versions not specified)
Description Stored Cross-Site Scripting occurs due to improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This allows for the execution of arbitrary JavaScript when other users access the affected page, which may lead to account takeover, credential theft, or redirection to a malicious website.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10079
CVE-2026-9292

Affected Products

Factorytalk® Datamosaix™ Private Cloud