CVE-2025-14272: Rockwell Automation Factorytalk Analytics Pavilionx

High severity, CVSS 8.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized actor to execute privileged operations, including user/role management and other administrative actions.

Affected products

Published 2026-06-16. Last modified 2026-10-07.