Status: UPDATED | Advisory ID: CVE-2026-9717
| CVE | CVE-2026-9717 |
| CVSS Score / Version | 7.2 (High) / CVSS v3.1 |
| Updated | 2026-07-01 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Schneider Electric powerlogic_p7_firmware and Schneider Electric PowerLogic™ P7 |
| Classified as | CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Schneider Electric | powerlogic_p7_firmware | ||
| Schneider Electric | PowerLogic™ P7 |
| Subsystems | General OT |
| Sectors | Multiple |
CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service.
Monitor Schneider Electric's web page for any future patch releases. See vendor advisory link below.