NONE · 0

CVE-2026-9292

A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows conf...

Vulnerability Description

A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-9292?

CVE-2026-9292 is a documented vulnerability. A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows conf...

How severe is CVE-2026-9292?

CVSS scoring is not yet available for CVE-2026-9292. Check NVD for updates.

Is there a patch for CVE-2026-9292?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.