Skip to content
Threat Feed
high advisory

Privilege Escalation Vulnerability in Rockwell Automation FactoryTalk Activation Manager

Rockwell Automation FactoryTalk Activation Manager versions V5.02 and below are vulnerable to local privilege escalation via insecure installer custom actions that spawn SYSTEM-level console windows.

CVE search metadata

CVE search record: CVE-2026-16675. KEV: no. Product: FactoryTalk Activation Manager (<= V5.02). Brief: Privilege Escalation Vulnerability in Rockwell Automation FactoryTalk Activation Manager. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rockwell-activation-manager-privesc/

Rockwell Automation FactoryTalk Activation Manager versions V5.02 and below are susceptible to a privilege escalation vulnerability tracked as CVE-2026-16675. The flaw originates from custom actions implemented within the software's installer process. During installation or repair operations, these custom actions spawn visible console windows that operate with SYSTEM-level privileges. An attacker who has already achieved local access on a Windows system can interact with or hijack these exposed console windows to execute arbitrary commands with SYSTEM permissions. This vulnerability is particularly critical in industrial environments where the affected management software may be present on engineering workstations or server infrastructure, potentially granting an attacker full control over the host OS. The vendor has released version V5.03 to address this security defect.

Impact

Successful exploitation allows a local authenticated user to gain full SYSTEM privileges on the affected host. This provides the attacker with total control over system processes, sensitive files, and configuration data. The impact is significant for industrial environments where engineering workstations could be compromised, potentially facilitating lateral movement into sensitive operational technology networks.

Recommendation

Prioritized actions for security and IT teams:

  • Upgrade all instances of Rockwell Automation FactoryTalk Activation Manager to version V5.03 or later immediately to patch CVE-2026-16675.
  • Audit industrial workstations for installations of FactoryTalk Activation Manager V5.02 and below to prioritize remediation.
  • Implement restrictive access controls for users on machines running industrial management software to limit the scope of potential local exploitation.
  • Use the provided Sigma rule to detect suspicious console window activity spawned by installation processes during software maintenance windows.

Immediate actions

Upgrade all FactoryTalk Activation Manager instances to V5.03.

IT Operations 72h

Mitigations

Upgrade to V5.03.

immediate IT Operations

CVE-2026-16675

Detection coverage 1

Detect FactoryTalk Activation Manager Privilege Escalation Attempt

high

Detects the spawning of cmd.exe or other shells by FactoryTalk Activation Manager installer processes, which may indicate exploitation of CVE-2026-16675.

sigma tactics: privilege_escalation techniques: T1068 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →