← All Advisories

CVE-2026-4827

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-4827

Key Details

CVECVE-2026-4827
CVSS Score / Version8.7 (High) / CVSS v4.0
Updated2026-06-17
Affected productssee table below
Classified asCWE-331 (Insufficient Entropy)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Schneider ElectricEasergy MiCOM C264
Schneider ElectricEasergy C5
Schneider ElectricEasergy MiCOM P30
Schneider ElectricEasergy MiCOM P40
Schneider ElectricEcoStruxure™ Power Automation System Gateway (EPAS-GTW)
Schneider ElectricEcoStruxure™ Power Automation System User Interface (EPAS-UI)
Schneider ElectricEcoStruxure™ Power Operation
Schneider ElectriciPMFLS
Schneider ElectricPowerLogic™ P5 Protection Relay
Schneider ElectricPowerLogic™ P7 Protection and Control Platform
Schneider ElectricPowerLogic™ T300
Schneider ElectricPowerLogic™ T500
Schneider ElectricSaitel DP
Schneider ElectricEasyLogic T150 (formerly Saitel DR)
SubsystemsGeneral OT
SectorsMultiple

What to Know

CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.

What to Do

Monitor Schneider Electric's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-4827
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-4827