CVE-2026-8045
CWE-611Published: June 9, 2026· Updated: Jun 9, 2026
Official Description
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.
Technical Analysis
CVE-2026-8045 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.
Exploitation requires low privileges, which limits the exposure to scenarios where an attacker has already gained initial access.
CVSS v3.1 Vector Breakdown
Exploit & PoC Resources
News & Research Mentioning CVE-2026-8045
View CSAF Summary Schneider Electric is aware of a vulnerability in its EcoStruxure™ IT Data Center Expert. The EcoStruxure™ IT Data Center Expert product is a scalable monitoring software that collects, organizes, and distributes critical device information providing a comprehensive view of equipment. Failure to apply the remediation provided below may risk information disclosure. The following versions of Schneider Electric EcoStruxure IT Data Center Expert are affected: EcoStruxure IT Data Center Expert vers:intdot/<=9.1.1, 9.1.2 (CVE-2026-8045) CVSS Vendor Equipment Vulnerabilities v3 6.5 Schneider Electric Schneider Electric EcoStruxure IT Data Center Expert Improper Restriction of XML External Entity Reference Background Critical Infrastructure [xlite_meta score:73 src:CISA Alerts xlite_fp:07220d55a317c3a0b7e50d85e9b175369f866d47be9592f32c07f2bf15ac55da]
All References (1)
Quick Facts
Related CVEs (CWE-611)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2026-8045 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts