PT-2026-84216 · Rockwell Automation · Factorytalk Activation Manager
CVE-2026-16675
·
Published
2026-09-01
·
Updated
2026-09-03
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FactoryTalk Activation Manager (affected versions not specified)
Description
A privilege escalation issue exists due to custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials can hijack these console windows to obtain a SYSTEM-level command prompt, granting unrestricted access to all files, processes, system resources, and industrial control systems.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Implement runtime segmentation in OT environments to limit the potential impact of an escalation.
LPE
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Factorytalk Activation Manager