CVE-2026-19233

8.6

Schneider Electric · EcoStruxure IT Data Center Expert

A Server-Side Request Forgery (SSRF) vulnerability in Schneider Electric EcoStruxure IT Data Center Expert allows privileged attackers to execute unauthorized commands and access sensitive server data.

Executive summary

An authenticated SSRF vulnerability in Schneider Electric EcoStruxure IT Data Center Expert exposes the system to unauthorized command execution and data disclosure.

Vulnerability

This vulnerability is a Server-Side Request Forgery (CWE-918) flaw triggered by sending crafted, unvalidated parameters to a server endpoint. Successful exploitation requires the attacker to possess an authenticated, privileged account.

Business impact

The ability to execute unauthorized commands and exfiltrate server data presents a severe risk to operational technology environments. Given the CVSS score of 8.6, this vulnerability is classified as High severity and could lead to significant compromise of data integrity and system control within the data center infrastructure.

Remediation

Immediate Action: Review the official security notice from Schneider Electric (SEVD-2026-251-01) and apply available security updates immediately upon release.

Proactive Monitoring: Monitor server access logs for unusual outbound requests or unexpected API calls originating from the Data Center Expert appliance.

Compensating Controls: Restrict administrative access to the management interface to trusted networks and implement network segmentation to prevent the application from reaching sensitive internal resources.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize identifying all instances of EcoStruxure IT Data Center Expert within their environment to prepare for patching. Until a formal update is deployed, ensure that only authorized personnel have access to the administrative interface to mitigate the risk of this privileged SSRF attack.

More Schneider Electric CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources