← Knowledge Center
Advisory CVE-2026-9292

Stored XSS in Rockwell FactoryTalk DataMosaix Enables Account Takeover

CISA has published an ICS advisory covering CVE-2026-9292, a stored cross-site scripting (XSS) vulnerability in Rockwell Automation’s FactoryTalk DataMosaix Private Cloud (versions 8.02 and earlier). The flaw arises from improper neutralization of user-supplied input in the Workflows configuration, letting a high-privileged authenticated attacker plant persistent malicious JavaScript on the server.

When other users load the affected page, the injected script executes in their browser session. Per the advisory, this can result in account takeover, credential theft, and redirection to attacker-controlled destinations \u2014 making it a genuine identity/access concern despite the CVSS 6.1 rating. Because DataMosaix is deployed across critical manufacturing environments worldwide, exploitation could give attackers a foothold in sensitive OT-adjacent systems.

What to take away: stored XSS is often underrated, but its ability to hijack authenticated sessions and steal credentials makes it a real identity risk. Organizations running affected DataMosaix versions should apply Rockwell’s fixes and review privileged account activity for signs of session compromise.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.