PT-2026-47813 · Schneider Electric · Data Center Expert
CVE-2026-8045
·
Published
2026-06-09
·
Updated
2026-07-20
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Schneider Electric Data Center Expert (affected versions not specified)
Description
An Improper Restriction of XML External Entity Reference (XXE) issue exists, which occurs when an application fails to restrict XML external entity references, potentially allowing the disclosure of internal server files. An attacker with a Data Center Expert user account can exploit this by submitting crafted XML payloads to SOAP service endpoints.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Data Center Expert