CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Schneider Electric EcoStruxure IT Data Center Expert

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 266

As cited

Copy frozen at (site build).

vulnerabilities

Schneider Electric EcoStruxure IT Data Center Expert

Schneider Electric has disclosed a vulnerability in EcoStruxure IT Data Center Expert versions 9.1.1 and prior that allows authenticated attackers to disclose server-side file contents through crafted XML payloads submitted to SOAP service endpoints. The vulnerability, identified as CVE-2026-8045, is an XML External Entity (XXE) reference flaw rated CVSS 6.5 medium. Version 9.1.2 contains a fix and is available for download.

Why it matters: Organizations running affected versions of this data center monitoring software should update to 9.1.2 immediately to prevent authenticated users from accessing sensitive server-side files.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Schneider Electric EcoStruxure IT Data Center Expert

Schneider Electric has disclosed a vulnerability in EcoStruxure IT Data Center Expert versions 9.1.1 and prior that allows authenticated attackers to disclose server-side file contents through crafted XML payloads submitted to SOAP service endpoints. The vulnerability, identified as CVE-2026-8045, is an XML External Entity (XXE) reference flaw rated CVSS 6.5 medium. Version 9.1.2 contains a fix and is available for download.

Why it matters: Organizations running affected versions of this data center monitoring software should update to 9.1.2 immediately to prevent authenticated users from accessing sensitive server-side files.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary