Schneider Electric Easergy, EcoStruxure, PowerLogic, and Saitel Products - Insufficient Entropy Session Hijacking Vulnerability (CVE-2026-4827)
First seen Sep 8, 2026 · Updated Sep 8, 2026 · CVSS 8.3
A high-severity vulnerability (CVE-2026-4827) affecting numerous Schneider Electric Easergy, EcoStruxure, PowerLogic, and Saitel protection relays, RTUs, gateways, and SCADA/HMI software stems from insufficient entropy in session token generation. An attacker on the network could exploit weak session-management protections to hijack sessions and perform unauthorized operations on critical electrical grid control and protection devices.
Technical Analysis
The vulnerability is classified as CWE-331 (Insufficient Entropy), where session identifiers or tokens generated by affected devices lack sufficient randomness, enabling a network-positioned attacker to predict or brute-force valid session values and hijack authenticated sessions without needing prior credentials (CVSS 3.1: 8.3, AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L). Affected products span a wide range of protection relays (Easergy MiCOM P30/P40 series, C264, C434), RTUs (Saitel DP, EasyLogic T150), and supervisory software (EPAS-GTW, EPAS-UI, EcoStruxure Power Operation, iPMFLS, PowerLogic P5/P7/T300/T500), meaning exploitation could allow unauthorized control or monitoring manipulation of substation automation and electrical distribution systems. Several product lines (P30 models P437/P532/P631/P634/P436/P438/P638 and certain P40 series variants) have no vendor fix yet and rely solely on network segmentation and reduced session timeout mitigations. This is a pure OT/ICS device-firmware and SCADA-software vulnerability with no direct interaction with AI agent frameworks, LLM tool use, or RAG pipelines, and there is no plausible agent-system impact to report for this advisory.
Affected Systems
Easergy MiCOM C264 (<=D7.33), Easergy MiCOM P139/P437/P439/P532/P539/P631/P632/P633/P634/P138/P436/P438/P638/C434 (various pre-fix firmware versions), Easergy MiCOM P40 Series (Protocol Option bit G/H/L, all firmware), Easergy C5 (<=1.1.17), EPAS-GTW (<=6.4.616.200.100), EPAS-UI (<=3.0.3), EcoStruxure Power Operation (2022 CU6 and prior, 2024 CU2 and prior), iPMFLS (<=64.2025.0.13), PowerLogic P5 (<=02.502.103), PowerLogic P7 (<=02.002.002), PowerLogic T300 (<=2.9.4), PowerLogic T500 (<=11.08.02), Saitel DP (<=11.06.36), EasyLogic T150/Saitel DR (<=11.06.30)
Indicators of Compromise
- No specific indicators of compromise published; vulnerability is a design weakness (CWE-331) rather than an observed exploit or malware artifact.
Remediation Steps
- 1
Apply vendor firmware/software updates
Update affected devices and software to the fixed versions specified by Schneider Electric (e.g., MiCOM C264 D7.34, Easergy C5 1.1.18, EPAS-GTW 6.4.610.500.101, EPO 2022 CU7/2024 CU3, PowerLogic P5/P7/T300/T500 fixed builds, Saitel DP 11.06.37, Saitel DR 11.06.31) and reboot devices as required.
- 2
Segment ICS networks
For products without an available fix (P30 models P437/P532/P631/P634/P436/P438/P638 and certain P40 series), place devices behind firewalls on physically or logically segmented OT networks, restricting access via IDS and firewall rules.
- 3
Reduce session inactivity timeout
Use the CAE tool to shorten the 'Minimum inactivity period' on affected relays to reduce the exploitation window for session hijacking.
- 4
Restrict remote access
Avoid exposing control system devices to the internet; require VPN with up-to-date patching for any necessary remote access, and ensure connected endpoints are secured.
- 5
Monitor and report
Monitor OT network traffic for anomalous session activity and report suspected malicious activity to CISA and Schneider Electric CPCERT.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.