CISA flags FactoryTalk DataMosaix XSS, Rockwell urges 8.03
The v3 medium score is the wrong comfort blanket for stored JavaScript that can steal credentials in an ICS-adjacent platform.
TL;DR
CISA issued ICSA-26-197-09 for CVE-2026-9292, a stored cross-site scripting flaw in Rockwell Automation FactoryTalk DataMosaix Private Cloud 8.02 and earlier. Authenticated high-privilege attackers can plant scripts in Workflows configuration, with potential account takeover, credential theft, or malicious redirection. Rockwell recommends upgrading to 8.03 or later; CISA says it has no known public exploitation reports.
Patch this on the v4 risk, not the v3 headline number. CISA rates CVE-2026-9292 at CVSS v3.1 6.1, but the same advisory gives it CVSS v4 8.4 and describes stored JavaScript in FactoryTalk DataMosaix Private Cloud Workflows configuration. That matters because the script persists on the server and executes when other users hit the affected page, which moves the practical risk from “annoying web bug” to account takeover, credential theft, or redirection to a malicious site. The privilege requirement is real: the attacker must be authenticated and high-privilege. It is not a reason to leave 8.02 sitting around in a contractor or managed service environment where admin accounts are exactly the thing attackers try to borrow first. Upgrade DataMosaix Private Cloud to 8.03 or later, and treat the open question as deployment timing, not whether this deserves a patch window.
Published ·Deep Fathom