Status: UPDATED
| Advisory ID: CVE-2026-8044
Key Details
| CVE | CVE-2026-8044 |
| CVSS Score / Version | 8.6 (High) / CVSS v4.0 |
| Updated | 2026-09-09 |
| Affected products | Schneider Electric EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) |
| Classified as | CWE-88 (Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as backup configuration parameters.
What to Do
Monitor Schneider Electric's web page for any future patch releases.
References