# Stored XSS Flaw Hits Rockwell DataMosaix

Published: 2026-07-16 · Severity: medium · Sectors: manufacturing, technology
Canonical: https://vorant.io/reports/5c2fb3ae-5e51-539e-982b-904b07274b66/stored-xss-flaw-hits-rockwell-datamosaix

> A stored cross-site scripting vulnerability in Rockwell Automation FactoryTalk DataMosaix Private Cloud could let authenticated attackers plant malicious scripts to hijack sessions.

CISA published an advisory for a stored cross-site scripting vulnerability (CVE-2026-9292) affecting Rockwell Automation's FactoryTalk DataMosaix Private Cloud, versions 8.02 and earlier. The flaw arises from improper neutralization of user-supplied input in the Workflows configuration, allowing an authenticated attacker with high privileges to permanently store malicious JavaScript on the server. When other users access the affected page, the script executes, potentially enabling account takeover, credential theft, or redirection to malicious sites.

The affected product is used in Critical Manufacturing and Information Technology sectors worldwide, with Rockwell Automation headquartered in the United States. Rockwell has released a fix in DataMosaix Private Cloud version 8.03 and recommends upgrading; organizations unable to update immediately should follow Rockwell's published security best practices. CISA notes no known public exploitation of this vulnerability has been reported at this time, and the requirement for high-privilege authentication limits the immediate risk, though the flaw could still be leveraged as part of a broader attack chain against industrial environments.

## Mentioned in this report

- Vulnerabilities: CVE-2026-9292

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-09

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5c2fb3ae-5e51-539e-982b-904b07274b66/stored-xss-flaw-hits-rockwell-datamosaix.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
