ics-otregulatorNewsThe Broadside1 min read

Rockwell FactoryTalk Activation Manager gets privilege escalation patch

An attacker with Windows credentials on the machine can hijack a console window spawned during install or repair to grab SYSTEM, update to V5.03 closes it.


TL;DR

CISA published an advisory for CVE-2026-16675 (CVSS 7.8), a privilege escalation vulnerability in Rockwell Automation FactoryTalk Activation Manager V5.02 and below. The flaw arises from custom installer actions that spawn visible console windows running with SYSTEM privileges during installation or repair. An authenticated attacker with Windows credentials can hijack those windows to obtain a SYSTEM-level command prompt, gaining full access to local files, processes, and system resources. Rockwell recommends updating to V5.03. No known public exploitation has been reported to CISA.

This is the latest in a string of advisories for FactoryTalk Activation Manager, a licensing tool that sits on engineering workstations across critical manufacturing environments. Prior CISA advisories for the product have covered remote code execution (CVE-2023-38545, CVSS 9.8 in 2024) and an authentication algorithm flaw (CVE-2025-7970, CVSS 7.5 in 2025). The pattern is worth noting: each time, the fix is a version bump, and each time organizations that can't patch immediately are left with Rockwell's standing recommendation to follow "security best practices."

CVE-2026-16675 doesn't require remote access or sophisticated tooling. The vulnerability is in the installer itself, custom actions spawn console windows with SYSTEM privileges, and an attacker who already has Windows credentials on the box can hijack them. The CVSS v3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) tells the story: local, low complexity, and the result is high impact across confidentiality, integrity, and availability. The CVSS v4 score of 8.5 confirms the assessment.

Rockwell's remediation is straightforward: update to V5.03. The advisory lists no interim workarounds beyond the vendor's general security best practices. CISA's recommended practices (minimizing network exposure, isolating control system networks behind firewalls, using VPNs for remote access, and conducting proper impact analysis before deploying defenses) all apply, but none of them directly address the console-window hijack vector.

Organizations running FactoryTalk Activation Manager V5.02 or below should verify their version and plan the update. The vulnerability requires authenticated local access, so the immediate practical risk depends on how tightly those workstations are controlled. The advisory attributes discovery to an anonymous researcher who reported to Rockwell Automation, which then reported to CISA.


Published ·Deep Fathom