CVE-2026-16675
Received Received - Intake

Privilege Escalation in FactoryTalk Activation Manager

Vulnerability report for CVE-2026-16675, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Rockwell Automation

Description

A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
rockwell_automation factorytalk_activation_manager *
rockwellautomation factorytalk_activation_manager to 5.03 (exc)
rockwellautomation factorytalk_activation_manager 5.03

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a privilege escalation vulnerability in Rockwell Automation's FactoryTalk Activation Manager. During installation or repair, the installer spawns console windows running with SYSTEM privileges. An authenticated attacker with Windows credentials could hijack these windows to gain a SYSTEM-level command prompt, allowing full access to files, processes, and system resources.

Detection Guidance

To detect this vulnerability, check the installed version of FactoryTalk Activation Manager. Run the command 'wmic product where "name like 'FactoryTalk%Activation%Manager'" get name, version' in Command Prompt. If the version is V5.02 or below, the system is vulnerable.

Impact Analysis

An attacker could gain full control over an affected system, including access to sensitive data, ability to install malware, or disrupt operations. This requires the attacker to have valid Windows credentials but could lead to complete system compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating compliance requirements under GDPR, HIPAA, or other regulations that mandate strict access controls and data protection measures.

Mitigation Strategies

Immediately upgrade FactoryTalk Activation Manager to version V5.03 or later. Download the latest version from Rockwell Automation's official website and apply the patch to all affected systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16675. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart