CVE-2026-19233: Schneider Electric Ecostruxure It Data Center Expert Formerly Known As Struxureware Data Center Expert
High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.
CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server endpoint.
Affected products
- Schneider Electric Ecostruxure It Data Center Expert Formerly Known As Struxureware Data Center Expert: up to and including 9.1.2
Published 2026-09-09. Last modified 2026-09-09.