Privilege Escalation Vulnerability in FactoryTalk® Activation Manager by Rockwell Automation
CVE-2026-16675

8.5HIGH

What is CVE-2026-16675?

A privilege escalation security issue exists within FactoryTalk® Activation Manager due to custom installer actions that create visible console windows with SYSTEM privileges. This vulnerability allows authenticated attackers with Windows credentials to exploit these console windows, granting them access to a SYSTEM-level command prompt. As a result, they could potentially gain full control over all files, processes, and resources on the affected system, posing significant risks to system integrity and security.

Affected Version(s)

FactoryTalk® Activation Manager Version 5.02 and below

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.