Status: UPDATED | Advisory ID: CVE-2026-6866
| CVE | CVE-2026-6866 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-06-24 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | see table below |
| Classified as | CWE-1188 (Initialization of a Resource with an Insecure Default) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Schneider Electric | ecostruxure_panel_server_pas400_firmware | ||
| Schneider Electric | ecostruxure_panel_server_pas600_firmware | ||
| Schneider Electric | ecostruxure_panel_server_pas600v2_firmware | ||
| Schneider Electric | ecostruxure_panel_server_pas800_firmware | ||
| Schneider Electric | ecostruxure_panel_server_pas800v2_firmware | ||
| Schneider Electric | EcoStruxure™ Panel Server |
| Subsystems | General OT |
| Sectors | Multiple |
CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.
Monitor Schneider Electric's web page for any future patch releases. See vendor advisory link below.