Status: UPDATED | Advisory ID: CVE-2026-4827
| CVE | CVE-2026-4827 |
| CVSS Score / Version | 8.7 (High) / CVSS v4.0 |
| Updated | 2026-06-17 |
| Affected products | see table below |
| Classified as | CWE-331 (Insufficient Entropy) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Schneider Electric | Easergy MiCOM C264 | ||
| Schneider Electric | Easergy C5 | ||
| Schneider Electric | Easergy MiCOM P30 | ||
| Schneider Electric | Easergy MiCOM P40 | ||
| Schneider Electric | EcoStruxure™ Power Automation System Gateway (EPAS-GTW) | ||
| Schneider Electric | EcoStruxure™ Power Automation System User Interface (EPAS-UI) | ||
| Schneider Electric | EcoStruxure™ Power Operation | ||
| Schneider Electric | iPMFLS | ||
| Schneider Electric | PowerLogic™ P5 Protection Relay | ||
| Schneider Electric | PowerLogic™ P7 Protection and Control Platform | ||
| Schneider Electric | PowerLogic™ T300 | ||
| Schneider Electric | PowerLogic™ T500 | ||
| Schneider Electric | Saitel DP | ||
| Schneider Electric | EasyLogic T150 (formerly Saitel DR) |
| Subsystems | General OT |
| Sectors | Multiple |
CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.
Monitor Schneider Electric's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-4827 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-4827 |