CVE-2026-8044
Awaiting Analysis Awaiting Analysis - Queue

Command Injection in SE Backup Configuration

Vulnerability report for CVE-2026-8044, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: Schneider Electric SE

Description

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as backup configuration parameters.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
schneider_electric ecostruxure_it_data_center_expert to 9.2 (exc)
schneider_electric ecostruxure_it_data_center_expert 9.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Argument Injection vulnerability (CWE-88) in Schneider Electric's EcoStruxure IT Data Center Expert software. It allows a privileged attacker to execute remote code by injecting malicious arguments into backup configuration parameters.

Detection Guidance

To detect CVE-2026-8044, check the installed version of Schneider Electric's EcoStruxure IT Data Center Expert software. Versions 9.1.2 and prior are vulnerable. Use commands like 'rpm -qa | grep ecostruxure' on Linux or check the installed programs list on Windows to verify the version.

Impact Analysis

An attacker with a privileged account could exploit this to execute arbitrary commands on the system, potentially leading to unauthorized access, data theft, or system compromise. The high CVSS score indicates significant risk of unauthorized command execution.

Compliance Impact

This vulnerability could lead to unauthorized remote code execution, potentially exposing sensitive data or systems. For GDPR, it may result in unauthorized access to personal data, violating confidentiality requirements. For HIPAA, it could compromise protected health information integrity and availability. Compliance may be impacted if the affected software processes regulated data.

Mitigation Strategies

Immediately upgrade to EcoStruxure IT Data Center Expert version 9.2 or later. After installation, restart the service and verify the update by checking the version in the web client. Test patches in a controlled environment before full deployment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8044. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart