Management Console XXE Exposes Server-Side Files

The risk is inside the management plane, not on the perimeter. In EcoStruxure IT Data Center Expert, an authenticated user can submit crafted XML to SOAP endpoints and make the server reveal file contents it was never meant to expose. Schneider Electric says CVE-2026-8045 affects EcoStruxure IT Data Center Expert 9.1.1 and earlier, and v9.1.2 fixes it. The product collects and distributes critical device information, so server-side file disclosure can expose configs, secrets, or other local data operators expect to stay inside the console.

Part of the PlainSec briefing for 2026-06-30

Sources