CVE-2026-16675

8.5

Rockwell Automation · FactoryTalk Activation Manager

A privilege escalation vulnerability in the FactoryTalk Activation Manager installer allows authenticated local users to obtain SYSTEM-level access via hijacked console windows.

Executive summary

Rockwell Automation FactoryTalk Activation Manager contains a critical privilege escalation vulnerability that allows an authenticated local attacker to gain full SYSTEM privileges.

Vulnerability

The vulnerability exists due to improper handling of custom installer actions, which spawn visible console windows running with SYSTEM privileges. An authenticated local user can hijack these windows during installation or repair operations to execute commands with elevated system authority.

Business impact

Successful exploitation of this flaw grants an attacker full control over the host operating system. Given the CVSS score of 8.5, this high-severity vulnerability poses a significant risk to organizational infrastructure, as it facilitates unauthorized access to sensitive files, processes, and system-wide resources, potentially leading to total system compromise.

Remediation

Immediate Action: Upgrade to FactoryTalk Activation Manager version 5.03 or later immediately to resolve the vulnerable installer behavior.

Proactive Monitoring: Monitor system logs for unexpected process execution or unauthorized attempts to initiate software repair or installation tasks.

Compensating Controls: Restrict local user access to the installation directories and limit the ability of non-privileged users to initiate or interact with installer-related processes.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this privilege escalation vulnerability necessitates immediate action, particularly for systems where multiple users maintain local access. Security teams should prioritize the deployment of the vendor-supplied patch to version 5.03 across all affected endpoints to eliminate the risk of SYSTEM-level compromise.

More Rockwell Automation CVEs

Sources