Stored Cross-Site Scripting Vulnerabilities in ArmorStart LT by Rockwell Automation
CVE-2026-19471

6.9MEDIUM

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-19471?

ArmorStart LT by Rockwell Automation is susceptible to multiple stored cross-site scripting vulnerabilities. These occur when unvalidated user input is saved on the server, leading to the execution of malicious scripts when other users access the impacted pages. Such vulnerabilities can compromise user data and application integrity, emphasizing the necessity for prompt remediation and secure coding practices.

Affected Version(s)

ArmorStart® LT v2.001 and below

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.