CVE-2026-19471 PUBLISHED

Rockwell Automation ArmorStart® LT Stored Cross-site scripting

Assigner: Rockwell
Reserved: 10.08.2026 Published: 01.09.2026 Updated: 01.09.2026

Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Rockwell Automation
Product ArmorStart® LT
Versions Default: unaffected
  • Version v2.001 and below is affected

Solutions

Upgrade to version  v2.002 https://compatibility.rockwellautomation.com/Pages/Downloads.aspx  or later.

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE