Schneider Electric EcoStruxure IT Data Center Expert XXE Vulnerability (CVE-2026-8045)
First seen Jul 6, 2026 · Updated Jul 6, 2026 · CVSS 6.5
A medium-severity XML External Entity (XXE) vulnerability affects Schneider Electric EcoStruxure IT Data Center Expert versions 9.1.1 and prior, allowing an authenticated attacker to disclose server-side file contents via crafted XML payloads to SOAP service endpoints. Schneider Electric has released version 9.1.2 to remediate the issue, and no known public exploitation has been reported.
Technical Analysis
The vulnerability (CVE-2026-8045, CWE-611: Improper Restriction of XML External Entity Reference) exists in the SOAP service endpoints of EcoStruxure IT Data Center Expert, a monitoring platform used to aggregate data center device telemetry. An attacker holding a valid Data Center Expert user account (PR:L) can submit crafted XML payloads containing external entity references to force the server to disclose local file contents (CVSS 3.1: 6.5, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N), impacting confidentiality only with no integrity or availability loss. This is a traditional ICS/data center monitoring software flaw rather than an internet-facing zero-day, and exploitation requires network access plus authenticated credentials. Organizations running AI agents or automation pipelines that rely on data-center telemetry from this product (e.g., agents ingesting facility monitoring data via SOAP/XML integrations) could have sensitive configuration files, credentials, or internal system data exposed through the XXE flaw, indirectly compromising agent-accessible secrets stored on the same host.
Affected Systems
Schneider Electric EcoStruxure IT Data Center Expert (formerly StruxureWare Data Center Expert) versions 9.1.1 and prior; fixed in version 9.1.2
Indicators of Compromise
- No specific IOCs published; vulnerability disclosed via CISA/CSAF advisory ICSA-26-181-03 and Schneider Electric CPCERT SEVD-2026-160-01
Remediation Steps
- 1
Upgrade to fixed version
Update EcoStruxure IT Data Center Expert to version 9.1.2, which contains the vendor fix for CVE-2026-8045.
- 2
Restrict network exposure
Ensure Data Center Expert and its SOAP endpoints are not accessible from the internet; place behind firewalls and isolate from business networks.
- 3
Enforce least-privilege accounts
Limit and audit user accounts with access to Data Center Expert, since exploitation requires authenticated access.
- 4
Use secure remote access
If remote access is required, use up-to-date VPN solutions rather than direct exposure of management interfaces.
- 5
Monitor for anomalous SOAP requests
Implement logging/monitoring of SOAP service traffic for unusual XML payloads indicative of XXE exploitation attempts.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.