Privilege Escalation Vulnerability in Rockwell Automation FactoryTalk Activation Manager
Rockwell Automation FactoryTalk Activation Manager versions V5.02 and below are vulnerable to local privilege escalation via insecure installer custom actions that spawn SYSTEM-level console windows.
CVE search metadata
CVE search record: CVE-2026-16675. KEV: no. Product: FactoryTalk Activation Manager (<= V5.02). Brief: Privilege Escalation Vulnerability in Rockwell Automation FactoryTalk Activation Manager. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rockwell-activation-manager-privesc/
Rockwell Automation FactoryTalk Activation Manager versions V5.02 and below are susceptible to a privilege escalation vulnerability tracked as CVE-2026-16675. The flaw originates from custom actions implemented within the software's installer process. During installation or repair operations, these custom actions spawn visible console windows that operate with SYSTEM-level privileges. An attacker who has already achieved local access on a Windows system can interact with or hijack these exposed console windows to execute arbitrary commands with SYSTEM permissions. This vulnerability is particularly critical in industrial environments where the affected management software may be present on engineering workstations or server infrastructure, potentially granting an attacker full control over the host OS. The vendor has released version V5.03 to address this security defect.
Impact
Successful exploitation allows a local authenticated user to gain full SYSTEM privileges on the affected host. This provides the attacker with total control over system processes, sensitive files, and configuration data. The impact is significant for industrial environments where engineering workstations could be compromised, potentially facilitating lateral movement into sensitive operational technology networks.
Recommendation
Prioritized actions for security and IT teams:
- Upgrade all instances of Rockwell Automation FactoryTalk Activation Manager to version V5.03 or later immediately to patch CVE-2026-16675.
- Audit industrial workstations for installations of FactoryTalk Activation Manager V5.02 and below to prioritize remediation.
- Implement restrictive access controls for users on machines running industrial management software to limit the scope of potential local exploitation.
- Use the provided Sigma rule to detect suspicious console window activity spawned by installation processes during software maintenance windows.
Immediate actions
Upgrade all FactoryTalk Activation Manager instances to V5.03.
Mitigations
Upgrade to V5.03.
CVE-2026-16675
Detection coverage 1
Detect FactoryTalk Activation Manager Privilege Escalation Attempt
highDetects the spawning of cmd.exe or other shells by FactoryTalk Activation Manager installer processes, which may indicate exploitation of CVE-2026-16675.
Detection queries are available on the platform. Get full rules →