← All Advisories

CVE-2026-14354

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-14354

Key Details

CVECVE-2026-14354
CVSS Score / Version8.7 (High) / CVSS v4.0
Updated2026-07-30
Affected productsSchneider Electric EcoStruxure™ Cybersecurity Admin Expert
Classified asCWE-522 (Insufficiently Protected Credentials)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Schneider ElectricEcoStruxure™ Cybersecurity Admin Expert
SubsystemsGeneral OT
SectorsMultiple

What to Know

CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker leverages weaknesses in the handling and protection of stored credentials within the application.

What to Do

Monitor Schneider Electric's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-14354
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-14354