Schneider Data Center Expert SOAP XEE Vulnerability
CVE-2026-8045 Published on June 9, 2026

CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.

NVD

Weakness Type

What is a XXE Vulnerability?

The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

CVE-2026-8045 has been classified to as a XXE vulnerability or weakness.


Products Associated with CVE-2026-8045

Want to know whenever a new CVE is published for Schneider Electric Data Center Expert? stack.watch will email you.

 

Affected Versions

Schneider Electric EcoStruxure™ IT Data Center Expert Version v9.1.1 and Prior is affected by CVE-2026-8045