mediumOther

Schneider Electric EcoStruxure IT Data Center Expert XXE Vulnerability (CVE-2026-8045)

First seen Jul 6, 2026 · Updated Jul 6, 2026 · CVSS 6.5

ICSSCADAXXEinformation-disclosuredata-centerschneider-electricCWE-611

A medium-severity XML External Entity (XXE) vulnerability affects Schneider Electric EcoStruxure IT Data Center Expert versions 9.1.1 and prior, allowing an authenticated attacker to disclose server-side file contents via crafted XML payloads to SOAP service endpoints. Schneider Electric has released version 9.1.2 to remediate the issue, and no known public exploitation has been reported.

Technical Analysis

The vulnerability (CVE-2026-8045, CWE-611: Improper Restriction of XML External Entity Reference) exists in the SOAP service endpoints of EcoStruxure IT Data Center Expert, a monitoring platform used to aggregate data center device telemetry. An attacker holding a valid Data Center Expert user account (PR:L) can submit crafted XML payloads containing external entity references to force the server to disclose local file contents (CVSS 3.1: 6.5, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N), impacting confidentiality only with no integrity or availability loss. This is a traditional ICS/data center monitoring software flaw rather than an internet-facing zero-day, and exploitation requires network access plus authenticated credentials. Organizations running AI agents or automation pipelines that rely on data-center telemetry from this product (e.g., agents ingesting facility monitoring data via SOAP/XML integrations) could have sensitive configuration files, credentials, or internal system data exposed through the XXE flaw, indirectly compromising agent-accessible secrets stored on the same host.

Affected Systems

Schneider Electric EcoStruxure IT Data Center Expert (formerly StruxureWare Data Center Expert) versions 9.1.1 and prior; fixed in version 9.1.2

Indicators of Compromise

  • No specific IOCs published; vulnerability disclosed via CISA/CSAF advisory ICSA-26-181-03 and Schneider Electric CPCERT SEVD-2026-160-01

Remediation Steps

  1. 1

    Upgrade to fixed version

    Update EcoStruxure IT Data Center Expert to version 9.1.2, which contains the vendor fix for CVE-2026-8045.

  2. 2

    Restrict network exposure

    Ensure Data Center Expert and its SOAP endpoints are not accessible from the internet; place behind firewalls and isolate from business networks.

  3. 3

    Enforce least-privilege accounts

    Limit and audit user accounts with access to Data Center Expert, since exploitation requires authenticated access.

  4. 4

    Use secure remote access

    If remote access is required, use up-to-date VPN solutions rather than direct exposure of management interfaces.

  5. 5

    Monitor for anomalous SOAP requests

    Implement logging/monitoring of SOAP service traffic for unusual XML payloads indicative of XXE exploitation attempts.

CVE / Advisory IDs

CVE-2026-8045

Industries Most Exposed

Information TechnologyCritical ManufacturingEnergy

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.