7.1
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.
Basic Information
ID
CVE-2026-8045
Source
schneider
Published
Jun 9, 2026 at 14:41
Modified
Jun 9, 2026 at 16:01
Affected Product
Vendor
Schneider Electric
Product
EcoStruxure™ IT Data Center Expert
Version
v9.1.1 and Prior
Affected Versions
Schneider Electric EcoStruxure™ IT Data Center Expert v9.1.1 and Prior