Executive Summary

CVE-2026-19472 is an improper neutralization of input flaw in the embedded webserver of Rockwell Automation ArmorStart LT distributed motor control units, allowing script injection that executes against other users of the interface or a loss of webserver availability. Because ArmorStart LT sits directly on motor circuits driving conveyors, pumps, and material handling, a compromised or offline management interface degrades operator visibility and control at the point where electrical load meets physical process.

Technical Exposure Breakdown

The vulnerable component is the device webserver used for configuration, diagnostics, and status monitoring. Per the grounding data, ArmorStart LT and its firmware are affected in the range up to and including v2.001. Patch status is unknown at time of writing.

Two distinct failure modes exist under this class of defect. The first is a stored or reflected cross-site scripting condition where attacker controlled input is not neutralized before being rendered back into a page. When an engineer or operator later loads that page, the injected script runs in the context of their authenticated session against the device. That gives an attacker a path to session hijacking, credential theft through the browser, or unauthorized configuration changes performed under a legitimate user's identity. The second failure mode is a loss of webserver availability, meaning the management plane can be forced offline while the drive itself continues operating in whatever state it was last commanded.

The attack vector is the HTTP or HTTPS management surface. Exploitation of the scripting path typically requires a second user to visit the poisoned page, so the practical threat model depends on how many personnel touch these interfaces and whether the network permits an attacker to reach the webserver in the first place. In a flat plant network with shared engineering workstations, that condition is trivially met.

OT Impact and Compliance Risk

ArmorStart LT is a motor starter, not a passive sensor. The consequence of a webserver compromise is not limited to information disclosure. An attacker executing script in an authenticated operator session can alter parameters or push configuration that changes how a motor responds, and a webserver outage removes the operator's window into device state during an event. Loss of visibility during a fault is itself a safety and process integrity problem.

Under IEC 62443, this maps directly to zone and conduit failures around human machine interfaces and the device management plane, and it stresses the FR2 use control and FR3 system integrity requirements. NERC CIP registered entities should treat any internet or corporate reachable ArmorStart LT webserver as an electronic access point that must be justified and logged under CIP-005 and CIP-007. Water and wastewater operators subject to AWIA 2018 risk and resilience assessments should count motor control webservers among the cyber dependent assets whose failure affects treatment continuity. Pipeline operators under TSA SD-02C should verify these interfaces fall inside a segmented control zone rather than in a general purpose network.

Compensating Controls

Do not rely solely on a firmware update, especially where patch status is unknown and maintenance windows on live motor circuits are constrained. Active scanning of these devices can brick industrial components, so avoid aggressive vulnerability scanners against the webserver and validate any tooling in a lab first.

BreachSpider Intel

BreachSpider tracks CVE-2026-19472 and related ArmorStart LT advisories across our OT exposure dataset, and continuous monitoring is available for operators who need to know when their motor control interfaces become reachable or exploited.