CVE-2026-19471: Rockwell Automation ArmorStart® LT Stored Cross-site scripting
Published Sep 1, 2026
·Updated
Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page.
Affected Software
1 affected component
Rockwell Automation ArmorStart® LT
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation ArmorStart® LTto a version that resolves this vulnerability.Fixed in v2.002
Event History
Sep 1, 2026
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·01:18 PM
DescriptionSeverityWeakness