CVE-2026-14354
Schneider Electric · EcoStruxure Cybersecurity Admin Expert
A vulnerability in Schneider Electric EcoStruxure Cybersecurity Admin Expert allows a local privileged attacker to bypass authentication and modify credentials.
Executive summary
A critical credential protection flaw in Schneider Electric EcoStruxure Cybersecurity Admin Expert enables local privileged attackers to compromise managed devices via authentication bypass.
Vulnerability
This vulnerability (CWE-522) involves the insufficient protection of stored credentials. It requires an attacker to already possess local high-level privileges (PR:H) to leverage the flaw, which then allows for unauthorized credential modification and authentication bypass.
Business impact
The ability to modify credentials within a cybersecurity administration tool is a high-impact event. With a CVSS score of 8.7, this vulnerability could allow an attacker to gain full control over the managed infrastructure, leading to systemic compromise of industrial or enterprise control systems and serious operational disruption.
Remediation
Immediate Action: Consult the official Schneider Electric security notice (SEVD-2026-195-02) and apply any available security updates or configuration hardening steps provided by the vendor.
Proactive Monitoring: Audit local system access logs and monitor for unauthorized attempts to access or modify credential storage files or administrative configuration settings.
Compensating Controls: Implement strict physical and logical access controls to the host machine to prevent unauthorized local access, as this vulnerability requires local privileges to exploit.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
While local access is a prerequisite, the potential for total system compromise makes this a high-priority issue for administrators of EcoStruxure environments. Ensure that all systems are updated as soon as the vendor releases the necessary patches and verify that administrative accounts are secured and monitored.