Stored XSS (CVE‑2026‑9292) in Rockwell Automation FactoryTalk DataMosaix Private Cloud Enables Credential Theft
What It Is — Rockwell Automation disclosed a stored cross‑site scripting (XSS) flaw (CVE‑2026‑9292) in FactoryTalk DataMosaix Private Cloud versions ≤ 8.02. An attacker with authenticated, high‑privilege access can inject malicious JavaScript into workflow configurations, which is then served to any user who views the compromised page.
Exploitability — The vulnerability is publicly assigned a CVSS v3 score of 6.1 (High). Exploitation requires valid credentials and privileged access, but no public PoC is known; however, the attack vector is well‑understood and easily reproducible once access is obtained.
Affected Products — Rockwell Automation FactoryTalk DataMosaix Private Cloud (≤ 8.02).
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (Security) and CC7.1 (Confidentiality) require robust input validation and protection against injection attacks; a stored XSS directly violates these controls.
- Continuous control monitoring must capture evidence that application‑level security patches are applied promptly, otherwise auditors will flag a control gap.
- Enterprise buyers in critical manufacturing increasingly demand proof of secure development practices; an unpatched XSS can erode trust and jeopardize SOC 2 attestation.
Recommended Actions
- Upgrade DataMosaix to version 8.03 or later, where the fix is included.
- Conduct a rapid code‑review of all custom workflow scripts to ensure proper sanitization.
- Map the vulnerability to SOC 2 control CC6.1, capture patch‑deployment evidence in your Trust Center, and schedule periodic scans for similar injection flaws.
- Enhance privileged‑access monitoring to detect anomalous script‑injection attempts.
Source: CISA Advisory – ICSA‑26‑197‑09