Rockwell Automation FactoryTalk Activation Manager

Summary

A privilege escalation vulnerability, CVE-2026-16675, exists in Rockwell Automation FactoryTalk Activation Manager versions V5.02 and below. This flaw allows an authenticated attacker to hijack console windows running with SYSTEM privileges during installation or repair to gain a SYSTEM-level command prompt. Rockwell Automation recommends updating to version V5.03 or following their security best practices.

IFF Assessment

FOE

The identified vulnerability allows for privilege escalation, granting attackers significant access to system resources, which is detrimental to defenders.

Severity

7.8 High

The CVSS score of 7.8 reflects a high severity due to the potential for privilege escalation to SYSTEM level, allowing full access to system resources by an authenticated attacker. The attack vector is local, but the impact is significant, affecting Confidentiality, Integrity, and Availability.

Defender Context

This vulnerability impacts critical manufacturing infrastructure and widespread deployments, posing a significant risk. Defenders should prioritize patching affected Rockwell Automation FactoryTalk Activation Manager instances to the latest version or implement strict access controls and monitoring to detect suspicious activity related to installation or repair processes.

Read Full Story →