All stories
highDefensive GuidanceCVE-2026-8045

High-Severity Vulnerability in Schneider Electric's EcoStruxure Exposes Server Files to Attackers

Schneider Electric has disclosed a vulnerability in its EcoStruxure IT Data Center Expert product. The flaw allows attackers to disclose server-side file contents via crafted XML payloads. This high-severity issue (CVSS 7.1) affects users with specific access rights and requires immediate attention from administrators to apply the recommended patch.

Summary

Schneider Electric has identified a critical vulnerability in its EcoStruxure IT Data Center Expert product, which could lead to information disclosure of server-side file contents. The vulnerability, assigned CVE-2026-8045, stems from an improper restriction of XML External Entity (XXE) references. This issue is rated as high severity with a CVSS score of 7.1 and affects users who have Data Center Expert user accounts. Schneider Electric has released a security advisory detailing the flaw and urging users to apply the necessary patches promptly.

What Happened

The vulnerability, identified as CVE-2026-8045, involves an XXE attack vector that allows attackers with specific access rights to submit crafted XML payloads to SOAP service endpoints. This can result in unauthorized disclosure of server-side file contents. The issue arises from improper handling of XML External Entity references within the EcoStruxure IT Data Center Expert product.

Technical Details

The vulnerability exists due to CWE-611, which involves improper restriction of XML External Entity reference. Attackers exploiting this flaw can manipulate XML payloads to access sensitive information stored on the server. This is particularly concerning for environments where users have elevated privileges or access rights within the EcoStruxure IT Data Center Expert system.

Affected Products and Fixed Versions

The vulnerability affects Schneider Electric's EcoStruxure IT Data Center Expert product. Users are advised to refer to the official security advisory for details on affected versions and the availability of patches. The advisory can be accessed at Schneider Electric Security Advisory.

Exploitation Status

As of the latest advisory, there have been no reports of active exploitation of this vulnerability. However, given its high severity and potential impact, Schneider Electric strongly recommends that all affected users apply the provided patches immediately to mitigate any risks.

Indicators of Compromise

Currently, specific indicators of compromise (IOCs) for this vulnerability are not publicly available. Users should monitor their systems for unusual XML activity or unauthorized access attempts as part of their defensive measures.

Detection Opportunities

While Schneider Electric has not released specific detection rules, organizations can enhance their monitoring by focusing on XML traffic to and from the EcoStruxure IT Data Center Expert product. Anomalies in SOAP service endpoint requests should be investigated promptly.

Timeline

  • May 14, 2026: Vulnerability disclosed by Schneider Electric.
  • June 30, 2026: Advisory released with patch details.

Why This Matters for Defenders

This vulnerability highlights the importance of timely patch management and monitoring for unusual activity within critical infrastructure systems. Organizations using Schneider Electric's EcoStruxure IT Data Center Expert should prioritize applying patches to prevent potential information disclosure incidents.

What Remains Unclear

  • Specific IOCs related to this vulnerability.
  • Detailed technical exploitation methods beyond what is publicly disclosed.

Defender Guidance

  1. Apply Patches: Immediately apply the patch provided by Schneider Electric to mitigate the vulnerability.
  2. Monitor XML Traffic: Enhance monitoring of XML traffic, particularly focusing on SOAP service endpoint requests.
  3. Review Access Controls: Ensure that only authorized users have Data Center Expert user accounts with access to sensitive information.

By following these steps, organizations can reduce their exposure to this high-severity vulnerability and protect their systems from potential exploitation.

Sources

  1. https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-03
  2. https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-01.pdf
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -