Source context: this article examines information published by the source on August 27, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.
What the vulnerability is
Rockwell Automation has identified a security flaw (CVE-2026-75112) in the OTTO Fleet Manager software. The issue stems from an insufficient work factor used in the bcrypt password hashing implementation. In practical terms, this means the computational effort required to hash passwords is too low, which reduces the resources and time an attacker would need to conduct offline brute-force attacks against stored credential hashes.
This vulnerability is not exploitable remotely. To leverage this flaw, an attacker must first gain access to an unencrypted system backup containing the password hashes.
Exposure and applicability
This vulnerability affects OTTO Fleet Manager versions 2.36.2 and all prior versions. The software is primarily utilized within critical manufacturing and transportation systems for fleet management operations.
Asset owners should evaluate their current deployment version and, more importantly, the security posture of their system backups. Because the attack vector requires access to backup files, the risk is highest in environments where backups are stored unencrypted or on shared network drives with broad access permissions.
Remediation priorities
Based on the vendor’s disclosure, we recommend the following prioritized actions for OT operators and security leads:
- Software Update: Upgrade to OTTO Fleet Manager version 2.36.3. This version addresses the insufficient work factor in the hashing implementation.
- Backup Encryption: For systems that cannot be immediately upgraded, enable encrypted system backups as detailed in Rockwell Automation security advisory SD1791. Encrypting backups directly addresses the primary attack vector by preventing an attacker from accessing the raw hashes needed for offline cracking.
- Access Control Review: Audit the storage and transmission of system backups. Ensure that backup files are stored in secure, restricted locations to limit the possibility of unauthorized access.
How to validate remediation
To verify that exposure has been reduced, operators should perform the following checks:
- Version Verification: Confirm through the software interface or system documentation that the installed version is 2.36.3 or later.
- Configuration Audit: If an upgrade was not possible, verify via the system settings that encrypted backups are enabled according to the guidance in advisory SD1791.
- Storage Validation: Confirm that backup destination folders have restricted permissions and that no unencrypted legacy backups remain on accessible network shares.
Limits and open questions
While updating the software or encrypting backups reduces the likelihood of successful credential compromise via this specific vector, it does not eliminate all risks associated with password security.
It remains unclear if previous versions of the software provided any alternative methods for securing hashes beyond the bcrypt implementation. Additionally, users should note that while encryption protects the backup files, it does not address how credentials are handled in memory or during active sessions; it specifically mitigates the risk of offline attacks against stored data.
Source and editorial note
Rockwell Automation OTTO Fleet Manager · Source date: August 27, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request an OT security assessment
Protect the systems your operations depend on.
Discuss your industrial environment, prioritize exposure, and establish evidence that safeguards work.
Request an OT assessment ↗