← All Advisories

CVE-2026-6866

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-6866

Key Details

CVECVE-2026-6866
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-06-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productssee table below
Classified asCWE-1188 (Initialization of a Resource with an Insecure Default)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Schneider Electricecostruxure_panel_server_pas400_firmware
Schneider Electricecostruxure_panel_server_pas600_firmware
Schneider Electricecostruxure_panel_server_pas600v2_firmware
Schneider Electricecostruxure_panel_server_pas800_firmware
Schneider Electricecostruxure_panel_server_pas800v2_firmware
Schneider ElectricEcoStruxure™ Panel Server
SubsystemsGeneral OT
SectorsMultiple

What to Know

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.

What to Do

Monitor Schneider Electric's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-6866
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-6866
Vendor advisoryhttps://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-132-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-132-04.pdf