Rockwell FactoryTalk PavilionX authorization bypass patched
Rockwell Automation patched CVE-2025-14272, an authorization flaw in FactoryTalk Analytics PavilionX allowing unauthorized privileged operations including user/role management.
Rockwell Automation disclosed a security vulnerability in FactoryTalk Analytics PavilionX versions prior to 7.01. The flaw, tracked as CVE-2025-14272, stems from improper authorization enforcement in API endpoints that could allow unauthorized actors to execute privileged operations. Successful exploitation enables attackers to perform administrative actions including user and role management without proper authentication.
The vulnerability affects installations worldwide in the critical manufacturing sector. Rockwell Automation has released version 7.01 to address the issue and recommends immediate patching through their Download Center. CISA notes the vulnerability has high attack complexity and no known public exploitation has been reported at this time.
Organizations using affected versions should prioritize the upgrade while implementing defense-in-depth measures including network isolation, minimizing internet exposure of control systems, and using secure remote access methods when required.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-01
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free