Rockwell Automation FactoryTalk DataMosaix
MonitorCVSS 6.1ICS-CERT ICSA-26-197-09Jul 14, 2026
Rockwell Automation
Summary
FactoryTalk DataMosaix Private Cloud contains a stored cross-site scripting (XSS) vulnerability that allows an attacker with system access to inject malicious JavaScript into stored fields. When other users view pages containing the injected code, the script executes in their browser, potentially allowing the attacker to steal credentials, hijack sessions, or perform unauthorized actions on behalf of the affected users.
What this means
What could happen
An attacker with access to FactoryTalk DataMosaix Private Cloud could inject malicious code that executes when other authorized users view affected pages, potentially allowing credential theft or unauthorized commands to be issued within the system.
Who's at risk
Operations teams and engineers using Rockwell Automation's FactoryTalk DataMosaix Private Cloud for data analysis and reporting should be aware that any user with system access could inadvertently introduce or be targeted by XSS attacks affecting other users' sessions and credentials.
How it could be exploited
An attacker with legitimate or compromised access to the DataMosaix system injects malicious JavaScript into a stored field (such as a report title, device name, or comment). When other users view pages containing that injected content, the malicious script executes in their browser with their privileges, allowing the attacker to steal session tokens, steal credentials, or perform actions on their behalf.
Prerequisites
- Access to FactoryTalk DataMosaix Private Cloud user account (legitimate or compromised)
- Ability to input data into fields that are displayed to other users without sanitization
- Target user must view a page containing the injected malicious content
No patch availableRequires authentication but compromised/insider accounts pose significant riskCould enable credential theft or unauthorized command execution
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (2)
1 with fix1 EOL
ProductAffected VersionsFix Status
FactoryTalk DataMosaix Private CloudAll versionsNo fix (EOL)
DataMosaix Private Cloud≤ 8.02Fix available
Remediation & Mitigation
0/4
Do now
0/3FactoryTalk DataMosaix Private Cloud
HARDENINGRestrict access to FactoryTalk DataMosaix Private Cloud to trusted users only; enforce strong authentication and regularly audit user accounts for unauthorized access
All products
HARDENINGMonitor DataMosaix audit logs for suspicious data entries or unusual field modifications that could indicate stored XSS injection attempts
WORKAROUNDImplement a Web Application Firewall (WAF) or reverse proxy in front of DataMosaix to sanitize user inputs and block known XSS payloads
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
FactoryTalk DataMosaix Private Cloud
HARDENINGSegment FactoryTalk DataMosaix Private Cloud on a separate VLAN with restricted network access to limit exposure if credentials are compromised
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/27be64a8-cfd2-4394-bcf3-52c0a7614458Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.