← All Advisories

Rockwell Automation FactoryTalk Historian SE Login Endpoint Race Condition Allows Unauthenticated Authentication Token Harvest

Last refreshed2026-10-07

Status: UPDATED  |  Advisory ID: CVE-2025-13036

Key Details

CVECVE-2025-13036
CVSS Score / Version9.2 (Critical) / CVSS v4.0
Updated2026-09-30
Affected productsRockwell Automation FactoryTalk Historian SE
Classified asCWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
Exploitation prediction (EPSS)0.29% probability of exploitation in the next 30 days (20% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Rockwell AutomationFactoryTalk Historian SE
SubsystemsSupervisory Control & Operations Platforms
SectorsMultiple

What to Know

An authentication

bypass security issue exists within FactoryTalk Historian Site Edition. By

continually sending requests to the login endpoint, an attacker may obtain a

valid authentication token. (NVD)

What to Do

Monitor Rockwell Automation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-13036
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-13036