CVE-2026-1227: Schneider Electric Ecostruxure Building Operation Webstation
High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files, interaction within the EBO system, or denial of service conditions when a local user uploads a specially crafted TGML graphics file to the EBO server from Workstation.
Affected products
- Schneider Electric Ecostruxure Building Operation Webstation
- Schneider Electric Ecostruxure Building Operation Workstation
Published 2026-02-11. Last modified 2026-06-17.