Insufficiently Protected Credentials in Schneider Electric Device Management App
CVE-2026-14354 Published on July 29, 2026

CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker leverages weaknesses in the handling and protection of stored credentials within the application.

NVD

Weakness Type

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.


Products Associated with CVE-2026-14354

Want to know whenever a new CVE is published for Schneider Electric Ecostruxure Cybersecurity Admin Expert? stack.watch will email you.

 

Affected Versions

Schneider Electric EcoStruxure™ Cybersecurity Admin Expert Version v4.2.0 and prior is affected by CVE-2026-14354