CISA Advisory: Rockwell Automation OTTO Fleet Manager Vulnerability CVE-2026-75112
CISA released an advisory on August 27, 2026, regarding a vulnerability in Rockwell Automation OTTO Fleet Manager, identified as CVE-2026-75112. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, weakly hashed credentials could be more easily compromised. The affected product is OTTO Fleet Manager versions up to and including V2.36.2. Rockwell Automation has addressed the vulnerability in software version 2.36.3. The vulnerability has a CVSS v3.1 base score of 6.8 (Medium) and CVSS v4.0 base score of 6.9 (Medium). It is not exploitable remotely and no public exploitation has been reported. CISA recommends defensive measures such as minimizing network exposure and following vendor mitigations.
What we know
Vulnerability is due to insufficient work factor in bcrypt password hashing.
▤ 1 sources›
Successful exploitation could reduce computational cost for offline brute-force attacks on password hashes.
▤ 1 sources›
CVSS v3.1 base score: 6.8 (Medium); CVSS v4.0 base score: 6.9 (Medium).
▤ 1 sources›
Affected product: Rockwell Automation OTTO Fleet Manager versions <= V2.36.2.
▤ 1 sources›
Rockwell Automation fixed the vulnerability in version 2.36.3.
▤ 1 sources›
CISA published an advisory on 2026-08-27 for CVE-2026-75112.
▤ 1 sources›
Attack requires access to unencrypted system backup.
▤ 1 sources›
Vulnerability is not exploitable remotely.
▤ 1 sources›
CISA published an advisory for a medium-severity vulnerability in Rockwell Automation OTTO Fleet Manager (CVE-2026-75112) due to insufficient bcrypt work factor, potentially enabling offline brute-force attacks on password hashes. Fixed in version 2.36.3.
Verified · 1 sourcesLive reports
View allComments 0
Discuss this event in persistent threads. Live chat remains separate.
No comments yet. Start the conversation.