CVE-2026-12661 PUBLISHED

FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability

Assigner: Rockwell
Reserved: 18.06.2026 Published: 01.09.2026 Updated: 01.09.2026

A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 4.8

Product Status

Vendor Rockwell Automation
Product FactoryTalk® Historian Machine Edition
Versions Default: unaffected
  • Version Series C: 7.101 Series B: 5.202 is affected

References

Problem Types

  • CWE-121 Stack-based buffer overflow CWE