PatchSiren cyber security CVE debrief
CVE-2025-12807 Rockwell Automation CVE debrief
CVE-2025-12807 is a high-severity issue in Rockwell Automation FactoryTalk DataMosaix Private Cloud. CISA’s advisory says low-privilege users can perform sensitive database operations through exposed API endpoints. The supplied CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) scores 8.8, so this should be treated as a serious exposure in environments running the affected product. The advisory’s revision history also labels the initial publication as a “FactoryTalk DataMosaix Private Cloud SQL Injection” issue, but the core defensive takeaway is the same: limit API exposure, assume low-privilege access paths may be abused, and apply the vendor correction promptly. Rockwell Automation’s stated fix is Version 8.01.02 or later.
- Vendor
- Rockwell Automation
- Product
- FactoryTalk DataMosaix Private Cloud
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-13
- Original CVE updated
- 2026-01-13
- Advisory published
- 2026-01-13
- Advisory updated
- 2026-01-13
Who should care
OT/ICS operators using FactoryTalk DataMosaix Private Cloud, Rockwell Automation administrators, SOC teams monitoring industrial environments, and vulnerability management teams responsible for API-facing services.
Technical summary
The source corpus describes a security issue in DataMosaix Private Cloud where users with low privilege can trigger sensitive database operations through exposed application programming interface (API) endpoints. The advisory metadata ties the issue to Rockwell Automation FactoryTalk DataMosaix Private Cloud and lists CVSS 3.1 as AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (8.8). Rockwell Automation’s remediation guidance is to update FactoryTalk DataMosaix Private Cloud to Version 8.01.02 or later; if upgrading is not possible, apply the vendor’s best security practices guidance.
Defensive priority
High. The issue is network-reachable, requires only low privileges, and is scored 8.8 with high confidentiality, integrity, and availability impact. Prioritize remediation for any exposed or production-connected deployments.
Recommended defensive actions
- Upgrade FactoryTalk DataMosaix Private Cloud to Version 8.01.02 or later.
- If immediate upgrade is not possible, follow Rockwell Automation’s best security practices guidance for the affected software.
- Review which API endpoints are exposed to users and networks, and restrict access to only necessary trusted principals and segments.
- Audit privileged and low-privilege account usage for unusual database activity tied to the application’s APIs.
- Treat this as an OT/ICS patching priority and validate the update in a controlled maintenance window before broad rollout.
Evidence notes
Supported by CISA CSAF advisory ICSA-26-013-02 for Rockwell Automation FactoryTalk DataMosaix Private Cloud, published 2026-01-13. The advisory text states that low-privilege users can perform sensitive database operations through exposed API endpoints. The supplied remediation lists Version 8.01.02 or later as the vendor fix. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, matching the 8.8 HIGH severity. No KEV listing is present in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-12807 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-12807
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-12807 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-12807
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-013-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-013-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.