Status: UPDATED
| Advisory ID: CVE-2026-19233
Key Details
| CVE | CVE-2026-19233 |
| CVSS Score / Version | 8.6 (High) / CVSS v4.0 |
| Updated | 2026-09-09 |
| Affected products | Schneider Electric EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) |
| Classified as | CWE-918 (Server-Side Request Forgery (SSRF)) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server endpoint.
What to Do
Monitor Schneider Electric's web page for any future patch releases.
References