← Terug naar overzicht

A privilege escalation vulnerability (CVE-2026-16675) exists in Rockwell Automation FactoryTalk Activation Manager V5.02 and below. The flaw stems from custom installer actions that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated local attacker can hijack these console windows to obtain a SYSTEM-level command prompt, granting full access to files, processes, and system resources. The vulnerability carries a CVSS v3.1 score of 7.8 (HIGH) and CVSS v4.0 score of 8.5 (HIGH). Affected sectors include Critical Manufacturing deployed worldwide. Rockwell Automation recommends updating to V5.03 to remediate the issue. No known public exploitation has been reported to CISA at this time.

Affected products

  • Rockwell Automation FactoryTalk Activation Manager V5.02 and below

Related CVE's

  • CVE-2026-16675

Categories

  • Critical Infrastructure
  • Enterprise Applications
  • Identity & Access