← All Advisories

CVE-2026-9717

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-9717

Key Details

CVECVE-2026-9717
CVSS Score / Version7.2 (High) / CVSS v3.1
Updated2026-07-01
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSchneider Electric powerlogic_p7_firmware and Schneider Electric PowerLogic™ P7
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Schneider Electricpowerlogic_p7_firmware
Schneider ElectricPowerLogic™ P7
SubsystemsGeneral OT
SectorsMultiple

What to Know

CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service.

What to Do

Monitor Schneider Electric's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-9717
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-9717
Vendor advisoryhttps://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-03.pdf