Rockwell Automation FactoryTalk Services Platform
MonitorCVSS 7.8ICS-CERT ICSA-26-202-07Jul 14, 2026
Rockwell Automation
Summary
Rockwell Automation FactoryTalk Services Platform (FTSP) contains a weak JWT (JSON Web Token) validation vulnerability that allows an attacker to bypass authentication without valid credentials. The platform fails to properly validate JWT tokens, enabling an attacker to forge authentication tokens and gain unauthorized access to the system. This affects all versions of FTSP. No vendor patch is currently available.
What this means
What could happen
An attacker who reaches your FactoryTalk Services Platform could bypass authentication and gain unauthorized access to manufacturing operations data and control systems, potentially allowing them to view sensitive production information or interfere with connected machinery.
Who's at risk
Manufacturing facilities using Rockwell Automation FactoryTalk Services Platform, particularly those running distributed control systems, MES (Manufacturing Execution Systems), or OPC servers that depend on FTSP for authentication and data integration. All manufacturing sectors relying on Rockwell infrastructure—automotive, food & beverage, pharmaceuticals, chemical processing, and discrete manufacturing—should assess their exposure.
How it could be exploited
An attacker sends a specially crafted authentication request to the FTSP web interface that exploits weak JWT validation logic, allowing them to forge a valid authentication token without knowing legitimate credentials. Once authenticated, they can interact with the platform as if they were an authorized user.
Prerequisites
- Network access to the FactoryTalk Services Platform web interface
- Knowledge of the JWT validation bypass technique
- FTSP instance exposed to the network or accessible from an attacker's position within your network
remotely exploitableweak authentication mechanismno patch availableaffects control system access
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (2)
1 pending1 EOL
ProductAffected VersionsFix Status
FactoryTalk Services Platform FTSPAll versionsNo fix (EOL)
FactoryTalk Directory (FTSP): 6.606.60No fix yet
Remediation & Mitigation
0/5
Do now
0/1WORKAROUNDRestrict network access to the FactoryTalk Services Platform to only authorized engineering workstations and administrative systems using firewall rules
Schedule — requires maintenance window
0/3Patching may require device reboot — plan for process interruption
FactoryTalk Directory (FTSP): 6.60
HARDENINGEnable and enforce strong authentication mechanisms (multi-factor authentication if available) for all FTSP user accounts
HARDENINGMonitor and log all authentication attempts to the FTSP platform for detection of suspicious activity
All products
HOTFIXContact Rockwell Automation for interim security updates or patched versions once available
Mitigations - no patch available
0/1FactoryTalk Services Platform FTSP has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGImplement network segmentation to isolate FTSP and dependent systems from untrusted networks
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/8049cce6-a925-4541-88aa-58e6936e5d5eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.