Security1 distinct publisher3 min readUpdated
CVE-2026-75112 in OTTO Fleet Manager puts warehouse automation on the same credential-handling footing as ordinary IT. Rockwell says it found the issue in routine internal testing.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Rockwell Automation has published an advisory titled "OTTO Fleet Manager - Weak Password Hashing Configuration," tracked as CVE-2026-75112, and says the issue was found internally during routine testing rather than reported from outside [1][2][3]. The product in question is not a back-office tool: Rockwell's own description calls OTTO Fleet Manager the enterprise-scale system supervisor for a fleet of autonomous mobile robots, managing work assignments, charging, parking and traffic so that materials move with minimal human intervention [4].
That description is the whole point. A weak password hash is a boring finding in a CRM and the same finding in a fleet supervisor, except that the account it eventually yields sits in front of machines that move pallets around people. The credential-handling debt of ordinary enterprise software has been ported into the aisle, and it arrives with the same characteristics: hashes at rest, backups that leave the cluster, operators who will not upgrade on the vendor's schedule.
The advisory's remedy is partly a build and partly a deployment exercise. OTTO Fleet Manager supports encrypted system backups as of version 2.36.3, using a passphrase chosen by the customer [6]. The passphrase is set when running cluster setup, and the restore workflow prompts for it when the backup being restored is encrypted [8]. On a fresh install, entering a non-blank passphrase is required and must be re-entered to confirm [9]. Changing it later means executing cluster setup again, where the options are Keep, Change, or Clear, with Clear removing the passphrase and disabling backup encryption outright [10]. Support for creating and restoring unencrypted backups remains [7]. So the protection exists, and so does the switch that turns it off; on an existing fleet it is reached only by upgrading and re-running cluster setup, not by a silent patch [1].
What Rockwell has not put in the body text we reviewed is the part operators need to triage. The advisory carries headings for "Affected Products and Solution" and "Security Issue Details for CVE-2026-75112," but the text supplied lists no affected version ranges, no severity score, and no weakness classification [13]. Customers who cannot move to a corrected version or apply the mitigations are pointed at Rockwell's general security best practices [5]. The most concrete technical hint is in the glossary, which defines bcrypt as a hashing algorithm using a salt and an adaptive cost factor to make brute force expensive, alongside definitions of password hashing and encryption [11][12]. That is a direction of travel, not a stated fix, and the advisory does not say what the software hashed with before.
Three things to watch. First, whether the affected-version and severity detail lands in the advisory's revision history, because without it asset owners cannot tell which of their clusters are in scope. Second, how many sites end up on 2.36.3 or later but with backup encryption cleared or never configured, since unencrypted backups remain a supported path [7][10]. Third, whether internally discovered issues in this line keep being published this way; Rockwell frames this disclosure as a transparency commitment, and that framing is testable over the next few advisories [3]. Questions on the disclosure go to Rockwell's PSIRT at [email protected] [14].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The advisory text reviewed contains headings for "Affected Products and Solution" and "Security Issue Details for CVE-2026-75112" but no affected version ranges, no severity score and no weakness classification in the body text.
Rockwell Automation published a security advisory titled "OTTO Fleet Manager - Weak Password Hashing Configuration" on its Trust Center security advisories pages.
Rockwell states the security issue was found internally during routine testing and is being reported based on its commitment to customer transparency and improvement of all business environments.
Rockwell describes OTTO Fleet Manager as enterprise-scale fleet management software that acts as the system supervisor for a fleet of OTTO autonomous mobile robots, managing work assignments, charging, parking and traffic so materials move efficiently with minimal human intervention.
The advisory says customers using the affected software who cannot upgrade to a corrected version or apply the listed mitigations should use Rockwell's security best practices.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary vendor advisory, materially incomplete
The claim set rests on a first-party Rockwell PSIRT advisory, which is the authoritative source for its own product and gives concrete, verifiable remediation mechanics. Evidence quality is capped by the absence of affected version ranges, a severity score and a weakness classification in the reviewed text, and by the lack of any second source or independent corroboration.
No uptake data in the record
The advisory documents that a fixed capability exists in version 2.36.3 but discloses no install base, no number of affected deployments, no customer upgrade figures and no exploitation activity. Adoption of either the vulnerable configuration or the encrypted-backup remediation cannot be measured from the supplied material without inventing facts.
Slightly understated by the vendor
The framing is conservative rather than inflated: Rockwell claims no more than that it found a weak password hashing configuration internally and shipped an optional encryption capability. If anything the disclosure understates the reader's decision problem, since a supervisory controller for autonomous mobile robot fleets is described without a severity score, weakness class or affected-version list, and the secure backup path remains opt-in with a Clear option that disables it.
Sole source is the affected vendor
Every claim in this cluster originates with the party whose product is defective. Rockwell controls the narrative of internal discovery, foregrounds a transparency commitment, omits severity and scope, and attaches a disclaimer denying any warranty as to completeness, timeliness or accuracy. Those are strong incentive pressures on framing, partially offset by the reputational cost of self-reporting a CVE at all.
Authoritative on mechanics, thin on scope
Confidence is moderate: the facts asserted here are drawn verbatim from an authoritative first-party advisory, so the existence of the CVE and the shape of the remediation are reliable. It is held down by single-source dependence, the absence of affected versions, severity and weakness classification, and the total lack of adoption or exploitation data.
build
GitLab bundles a zero-click GraphQL flaw with a CSRF bug, and only one needs a victim1 distinct publisher
security
CDN Tsunami: the protocol translation you pay for is the amplifier1 distinct publisher
security
A volunteer SOC for 45,000 water systems: what the Water Watch Center asks of operators1 distinct publisher
build
ShieldBreak: a Defender-to-SYSTEM PoC that your last patch cycle did not stop1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026