Executive Summary
In July 2026, a critical vulnerability (CVE-2026-10714) was identified in Rockwell Automation's FactoryTalk Services Platform (FTSP) version 6.60. The flaw allows attackers to bypass JSON Web Token (JWT) signature validation during Okta Web Authentication by setting the algorithm to "none," enabling low-privilege users to impersonate authorized users. This could lead to unauthorized access to system configurations and the ability to grant permissions to other systems protected by FTSP. (rockwellautomation.com)
This incident underscores the importance of robust authentication mechanisms in industrial control systems. As cyber threats targeting critical infrastructure become more sophisticated, organizations must prioritize timely patching and adherence to security best practices to mitigate potential risks.
Why This Matters Now
The exploitation of CVE-2026-10714 highlights the urgent need for organizations to review and strengthen their authentication processes, especially in systems integrated with third-party identity providers like Okta. Immediate action is required to apply patches and prevent potential breaches that could compromise critical infrastructure.
Attack Path Analysis
An attacker exploits a JWT signature validation bypass in FactoryTalk Services Platform to impersonate authorized users, escalating privileges to access system configurations. They then move laterally to other systems protected by FTSP, establish command and control channels, exfiltrate sensitive data, and potentially disrupt operations.
Kill Chain Progression
Initial Compromise
Description
An attacker exploits a JWT signature validation bypass in FactoryTalk Services Platform (FTSP) to impersonate authorized users.
Related CVEs
CVE-2026-10714
CVSS 8.8A vulnerability in FactoryTalk Services Platform allows an attacker to bypass JWT signature validation during Okta Web Authentication, potentially leading to unauthorized access to system configurations.
Affected Products:
Rockwell Automation FactoryTalk Services Platform – 6.60
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Modify Authentication Process
Access Token Manipulation
SAML Tokens
Multi-Factor Authentication Interception
SIP and Trust Provider Hijacking
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Identification and Authentication (Organizational Users)
Control ID: IA-2
PCI DSS 4.0 – Strong Authentication for Users and Administrators
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 6
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA Zero Trust Maturity Model 2.0 – Identity
Control ID: Pillar 1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Industrial Automation
Critical vulnerability in Rockwell FactoryTalk Services Platform enables JWT authentication bypass, allowing privilege escalation and unauthorized access to manufacturing control systems.
Automotive
Manufacturing operations using FactoryTalk Services Platform face authentication vulnerabilities that could compromise production line controls and enable lateral movement across systems.
Oil/Energy/Solar/Greentech
Energy sector infrastructure relying on Rockwell automation systems vulnerable to authentication bypass attacks targeting critical manufacturing and process control environments.
Electrical/Electronic Manufacturing
Electronics manufacturers using affected FactoryTalk platforms risk unauthorized configuration changes and system compromise through weak JWT authentication validation mechanisms.
Sources
- Rockwell Automation FactoryTalk Services Platformhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-202-07Verified
- Rockwell Automation Security Advisory SD1786https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1786.htmlVerified
- NVD - CVE-2026-10714https://nvd.nist.gov/vuln/detail/CVE-2026-10714Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely constrain the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit the JWT signature validation bypass may be limited by enforcing strict identity-based access controls.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could be constrained by limiting access to critical system configurations.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement may be restricted by controlling east-west traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels could be constrained by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may be limited by enforcing strict egress policies.
The attacker's ability to disrupt operations could be constrained by limiting access to critical systems.
Impact at a Glance
Affected Business Functions
- System Configuration Management
- User Access Control
Estimated downtime: 3 days
Estimated loss: $50,000
Unauthorized access to system configurations and potential privilege escalation.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent lateral movement.
- • Deploy East-West Traffic Security controls to monitor and restrict internal traffic flows.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across environments.
- • Apply Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Regularly update and patch systems to mitigate known vulnerabilities like CVE-2026-10714.



