CVE-2026-12661
Received Received - Intake

Buffer Overflow in FactoryTalk Historian Machine Edition

Vulnerability report for CVE-2026-12661, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Rockwell Automation

Description

A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
rockwellautomation factorytalk_historian_machine_edition *
rockwell_automation factorytalk_historian_machine_edition *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service issue in FactoryTalk Historian Machine Edition. An authenticated attacker on the same network can send specially crafted requests to the web interface, causing a buffer overflow. This may crash the device, making it unresponsive.

Detection Guidance

Detecting this vulnerability requires monitoring for buffer overflow conditions or crashes in FactoryTalk Historian Machine Edition. Check logs for unusual requests to the web interface or unexpected device unresponsiveness. No specific commands are provided in the context.

Impact Analysis

The vulnerability could disrupt operations by causing the affected device to crash and become unresponsive. This may lead to loss of critical data collection or monitoring capabilities in industrial environments.

Mitigation Strategies

Apply vendor patches or updates if available. Restrict network access to the web interface to trusted sources only. Monitor device performance for crashes and investigate any unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12661. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart