Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Rockwell Automation OTTO Fleet Manager Password Hashing Vulnerability

Source context: this article examines information published by the source on August 27, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.

What the vulnerability is

CVE-2026-75112 is a vulnerability involving the use of a password hash with insufficient computational effort (CWE-916) within Rockwell Automation OTTO Fleet Manager. The issue stems from an insufficient work factor in the bcrypt hashing implementation. This technical deficiency reduces the computational resources required for an attacker to perform offline brute-force attacks against stored password hashes.

Exposure and applicability

This vulnerability affects Rockwell Automation OTTO Fleet Manager versions 2.36.2 and earlier.

Exposure is not remote; exploitation requires the attacker to first obtain access to an unencrypted system backup containing the stored hashes. This makes the risk highest for organizations that store backups in insecure locations or fail to encrypt their backup archives.

Remediation priorities

Our analysis suggests prioritizing remediation based on the current state of backup security and the ability to perform software updates:

  1. Software Update: The primary corrective action is updating OTTO Fleet Manager to version 2.36.3, which addresses the hashing work factor.
  2. Backup Encryption: For environments where an immediate update is not feasible, enabling encrypted system backups (as detailed in Rockwell Automation security advisory SD1791) serves as a critical compensating control. This limits the utility of a stolen backup by preventing direct access to the hashes.
  3. Access Control: Restricting access to the systems and storage volumes where backups are maintained reduces the likelihood of an attacker obtaining the necessary files for an offline attack.

How to validate remediation

Verification must go beyond confirming a version number, as software updates do not inherently secure previously created unencrypted backups.

  • Version Verification: Confirm that the installed instance is running version 2.36.3 or later.
  • Configuration Audit: For those relying on compensating controls, verify through system settings or configuration logs that encrypted system backups are active and enforced.
  • Backup Inventory: Identify all existing legacy backups created under versions $\le$V2.36.2. These files remain vulnerable to offline cracking regardless of the current software version; they should be encrypted or securely deleted if no longer required.

Limits and open questions

Updating the software improves the hashing strength for new passwords but does not automatically re-hash existing credentials or encrypt historical backups created with the vulnerable version. There is a residual risk that legacy, unencrypted backups remain stored in archives or offsite storage, providing a persistent window for offline attacks.

It remains unclear if the update to 2.36.3 forces a password reset or automatically upgrades the work factor for existing hashes upon the first user login.

Source and editorial note

Rockwell Automation OTTO Fleet Manager · Source date: August 27, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment