PT-2026-58084 · Rockwell Automation · Factorytalk® Datamosaix™ Private Cloud
CVE-2026-9292
·
Published
2026-07-14
·
Updated
2026-07-14
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
FactoryTalk DataMosaix Private Cloud (affected versions not specified)
Description
Stored Cross-Site Scripting occurs due to improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This allows for the execution of arbitrary JavaScript when other users access the affected page, which may lead to account takeover, credential theft, or redirection to a malicious website.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Factorytalk® Datamosaix™ Private Cloud