Rockwell Automation FactoryTalk Services Platform Authentication Vulnerability
A security flaw in Rockwell Automation's FactoryTalk Services Platform allows attackers to impersonate other users. By forging login tokens, an unauthorized person could gain access to system settings. Users are advised to install the February 2026 patch to fix this.

English Brief
A security flaw in Rockwell Automation's FactoryTalk Services Platform allows attackers to impersonate other users. By forging login tokens, an unauthorized person could gain access to system settings. Users are advised to install the February 2026 patch to fix this.
الموجز العربي
ثغرة أمنية في نظام منصة خدمات روكويل أوتوميشن فاكتوري توك
تم اكتشاف ثغرة أمنية في منصة Rockwell Automation FactoryTalk Services Platform تتيح للمهاجمين انتحال صفة المستخدمين الآخرين. من خلال تزوير رموز تسجيل الدخول، يمكن لشخص غير مصرح له الوصول إلى إعدادات النظام. يُنصح المستخدمون بتثبيت التحديث الصادر في فبراير 2026 لإصلاح هذه المشكلة.
- 1Identify affected version: Check if FactoryTalk Services Platform is version 6.60
- 2Apply Security Patch: Download and install RAID 1158263 or February 2026 Roll-up
- 3Verify Integrity: Ensure FTSP services are restarted and JWT validation is enforced
English Advisory
// Intelligence Summary
A vulnerability (CVE-2026-10714) has been identified in Rockwell Automation FactoryTalk Services Platform (FTSP) 6.60, stemming from improper JWT signature validation during Okta Web Authentication. An attacker can leverage this to forge tokens by setting the algorithm header to 'none', allowing impersonation of authorized users.
التقرير العربي
// ملخص استخباراتي
تم تحديد ثغرة أمنية (CVE-2026-10714) في منصة Rockwell Automation FactoryTalk Services Platform (FTSP) الإصدار 6.60، ناتجة عن عدم التحقق من توقيع رموز JWT بشكل صحيح أثناء المصادقة عبر Okta Web. يمكن للمهاجم استغلال ذلك لتزوير الرموز عبر ضبط ترويسة الخوارزمية على 'none'، مما يتيح انتحال صفة المستخدمين المصرح لهم.
// Technical Context
The flaw exists because the application fails to enforce RSA algorithm usage for JWT validation. By manipulating the JWT header, a low-privilege attacker can bypass authentication checks, gain administrative-level access to system configurations, and modify permissions for downstream systems integrated with FTSP.
// السياق الفني
تكمن الثغرة في فشل التطبيق في فرض استخدام خوارزمية RSA للتحقق من رموز JWT. من خلال التلاعب بترويسة JWT، يمكن لمهاجم يمتلك صلاحيات منخفضة تجاوز ضوابط المصادقة، والحصول على وصول بمستوى المسؤول إلى إعدادات النظام، وتعديل الأذونات للأنظمة المتكاملة مع FTSP.
// Exposure Notes
The vulnerability affects FTSP 6.60. While not exploitable remotely, the impact is significant due to potential privilege escalation within critical manufacturing environments. The CVSS 3.1 base score is 7.8 (High).
// ملاحظات التعرض
تؤثر الثغرة على FTSP الإصدار 6.60. على الرغم من أنها غير قابلة للاستغلال عن بُعد، إلا أن التأثير كبير نظراً لاحتمالية تصعيد الصلاحيات داخل بيئات التصنيع الحيوية. تبلغ درجة الخطورة حسب مقياس CVSS 3.1 نحو 7.8 (عالية).
// Defensive Priority
Immediate application of the February 2026 Patch Roll-up or individual patch RAID 1158263 is critical. In environments where patching is delayed, organizations should restrict network access to affected controllers and implement strict segmentation from business networks as per defense-in-depth principles.
// أولوية الدفاع
يعد تطبيق تحديث فبراير 2026 أو الرقعة الفردية RAID 1158263 أمراً ضرورياً. في البيئات التي يتعذر فيها التحديث فوراً، يجب على المؤسسات تقييد الوصول إلى الشبكة الخاصة بأجهزة التحكم وتطبيق عزل صارم عن شبكات الأعمال وفقاً لمبادئ الدفاع في العمق.
Mitigation Checklist
- 1Identify affected version: Check if FactoryTalk Services Platform is version 6.60
- 2Apply Security Patch: Download and install RAID 1158263 or February 2026 Roll-up
- 3Verify Integrity: Ensure FTSP services are restarted and JWT validation is enforced
- 4Segment Networks: Ensure all FTSP instances are isolated behind firewalls and unreachable from the internet
- 5Review Logs: Monitor for unauthorized login attempts or unexpected privilege escalation events
قائمة إجراءات التخفيف
- 1تحديد الإصدار المتأثر: تحقق مما إذا كان إصدار منصة FTSP هو 6.60
- 2تطبيق الرقعة الأمنية: قم بتنزيل وتثبيت RAID 1158263 أو التحديث التراكمي لشهر فبراير 2026
- 3التحقق من النزاهة: تأكد من إعادة تشغيل خدمات FTSP والتحقق من فرض خوارزميات JWT
- 4عزل الشبكات: تأكد من عزل جميع خوادم FTSP خلف جدران حماية ومنع الوصول إليها من الإنترنت
- 5مراجعة السجلات: راقب محاولات تسجيل الدخول غير المصرح بها أو أي أنشطة تصعيد صلاحيات غير متوقعة
- Source: CISA Alerts
# Remediation Checklist for Rockwell Automation FTSP
# 1. Identify affected version: Check if FactoryTalk Services Platform is version 6.60
# 2. Apply Security Patch: Download and install RAID 1158263 or February 2026 Roll-up
# 3. Verify Integrity: Ensure FTSP services are restarted and JWT validation is enforced
# 4. Segment Networks: Ensure all FTSP instances are isolated behind firewalls and unreachable from the internet
# 5. Review Logs: Monitor for unauthorized login attempts or unexpected privilege escalation events