VYPR
advisoryPublished Jul 21, 2026· 1 source

Rockwell Automation FactoryTalk Services Platform Vulnerable to Authentication Bypass

A critical vulnerability in Rockwell Automation's FactoryTalk Services Platform allows attackers to forge authentication tokens, potentially impersonating authorized users.

Rockwell Automation's FactoryTalk Services Platform (FTSP) is affected by a critical authentication bypass vulnerability, identified as CVE-2026-10714. This flaw resides within the platform's handling of JSON Web Tokens (JWT) during Okta Web Authentication, enabling an attacker to bypass signature validation.

The vulnerability arises because the application fails to properly verify that the JWT algorithm is configured for RSA. An attacker can exploit this by setting the JWT algorithm to "none," allowing them to craft forged authentication tokens. This bypass mechanism is a significant security weakness that undermines the integrity of the authentication process.

Successful exploitation of CVE-2026-10714 could permit a low-privilege user to impersonate any authorized user on the FTSP server. This impersonation grants unauthorized access to sensitive system configurations and potentially allows the attacker to modify access controls or grant elevated permissions to other systems that rely on FTSP for authentication.

The vulnerability specifically impacts Rockwell Automation FactoryTalk Directory (FTSP) version 6.60. This version is known to be affected and requires immediate attention from users and administrators. The scope of deployment for this platform is worldwide, indicating a broad potential impact across various critical manufacturing sectors.

Rockwell Automation has provided a patch (RAID 1158263) and a February 2026 Patch Roll-up, or later updates, to address this vulnerability. Users unable to upgrade immediately are advised to implement Rockwell's security best practices and refer to their security advisory SD1786 for further mitigation guidance. These mitigations may include network segmentation and minimizing exposure.

CISA has assigned a CVSS v3.1 base score of 7.8 (HIGH) and a CVSS v4.0 score of 8.8 (HIGH) to this vulnerability. The attack vector is local, requiring a low privilege, but the impact on confidentiality, integrity, and availability is high, with a complex attack complexity. While not exploitable remotely, the potential for an authenticated low-privilege user to gain administrative control makes it a serious concern.

CISA recommends that organizations minimize network exposure for all control system devices, isolate them behind firewalls, and use secure remote access methods like VPNs. Organizations should also perform thorough impact and risk assessments before deploying any defensive measures. No public exploitation has been reported to CISA at this time, but the severity warrants proactive patching and security hardening.

Synthesized by Vypr AI