CVE-2026-8045
Awaiting Analysis
Awaiting Analysis - Queue
Improper XXE in Schneider Electric Data Center Expert
Publication date: 2026-06-09
Last updated on: 2026-06-09
Assigner: Schneider Electric SE
Description
Description
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| schneider_electric | ecostruxure_it_data_center_expert | to 9.1.2 (exc) |
| schneider_electric | ecostruxure_it_data_center_expert | 9.1.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-611 | The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. |