Security1 publisher3 min readPublished
Rockwell found weak password hashing in its own robot fleet supervisor
CVE-2026-75112 in OTTO Fleet Manager puts warehouse automation on the same credential-handling footing as ordinary IT. Rockwell says it found the issue in routine internal testing.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Rockwell Automation published a security advisory titled "OTTO Fleet Manager - Weak Password Hashing Configuration" on its Trust Center security advisories pages.
- The advisory identifies the security issue as CVE-2026-75112.
- Rockwell states the security issue was found internally during routine testing and is being reported based on its commitment to customer transparency and improvement of all business environments.
- Rockwell describes OTTO Fleet Manager as enterprise-scale fleet management software that acts as the system supervisor for a fleet of OTTO autonomous mobile robots, managing work assignments, charging, parking and traffic so materials move efficiently with minimal human intervention.
- The advisory says customers using the affected software who cannot upgrade to a corrected version or apply the listed mitigations should use Rockwell's security best practices.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Rockwell Automation has published an advisory titled "OTTO Fleet Manager - Weak Password Hashing Configuration," tracked as CVE-2026-75112, and says the issue was found internally during routine testing rather than reported from outside [1][2][3]. The product in question is not a back-office tool: Rockwell's own description calls OTTO Fleet Manager the enterprise-scale system supervisor for a fleet of autonomous mobile robots, managing work assignments, charging, parking and traffic so that materials move with minimal human intervention [4].
That description is the whole point. A weak password hash is a boring finding in a CRM and the same finding in a fleet supervisor, except that the account it eventually yields sits in front of machines that move pallets around people. The credential-handling debt of ordinary enterprise software has been ported into the aisle, and it arrives with the same characteristics: hashes at rest, backups that leave the cluster, operators who will not upgrade on the vendor's schedule.
The advisory's remedy is partly a build and partly a deployment exercise. OTTO Fleet Manager supports encrypted system backups as of version 2.36.3, using a passphrase chosen by the customer [6]. The passphrase is set when running cluster setup, and the restore workflow prompts for it when the backup being restored is encrypted [8]. On a fresh install, entering a non-blank passphrase is required and must be re-entered to confirm [9]. Changing it later means executing cluster setup again, where the options are Keep, Change, or Clear, with Clear removing the passphrase and disabling backup encryption outright [10]. Support for creating and restoring unencrypted backups remains [7]. So the protection exists, and so does the switch that turns it off; on an existing fleet it is reached only by upgrading and re-running cluster setup, not by a silent patch [1].
What Rockwell has not put in the body text we reviewed is the part operators need to triage. The advisory carries headings for "Affected Products and Solution" and "Security Issue Details for CVE-2026-75112," but the text supplied lists no affected version ranges, no severity score, and no weakness classification [13]. Customers who cannot move to a corrected version or apply the mitigations are pointed at Rockwell's general security best practices [5]. The most concrete technical hint is in the glossary, which defines bcrypt as a hashing algorithm using a salt and an adaptive cost factor to make brute force expensive, alongside definitions of password hashing and encryption [11][12]. That is a direction of travel, not a stated fix, and the advisory does not say what the software hashed with before.
Three things to watch. First, whether the affected-version and severity detail lands in the advisory's revision history, because without it asset owners cannot tell which of their clusters are in scope. Second, how many sites end up on 2.36.3 or later but with backup encryption cleared or never configured, since unencrypted backups remain a supported path [7][10]. Third, whether internally discovered issues in this line keep being published this way; Rockwell frames this disclosure as a transparency commitment, and that framing is testable over the next few advisories [3]. Questions on the disclosure go to Rockwell's PSIRT at rasecure@ra.rockwell.com [14].