CVE-2026-8045
CVSS 6.5 MEDIUM: cWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information… EPSS 0.2% (14th percentile).
Vulnerabilities · 76 days ago
The risk is inside the management plane, not on the perimeter. In EcoStruxure IT Data Center Expert, an authenticated user can submit crafted XML to SOAP endpoints and make the server reveal file contents it was never meant to expose.
Schneider Electric says CVE-2026-8045 affects EcoStruxure IT Data Center Expert 9.1.1 and earlier, and v9.1.2 fixes it. The product collects and distributes critical device information, so server-side file disclosure can expose configs, secrets, or other local data operators expect to stay inside the console.
CVSS 6.5 MEDIUM: cWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information… EPSS 0.2% (14th percentile).
1 source covering this story
Schneider Electric EcoStruxure IT Data Center Expert | CISA
Schneider Electric EcoStruxure IT Data Center Expert Summary Schneider Electric is aware of a vulnerability in its EcoStruxure™ IT Data Center Expert.
Part of the PlainSec briefing for 2026-06-30