CVE-2026-2273: Schneider Electric Ecostruxure Automation Expert
High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.
CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent system when an authenticated user opens a malicious project file.
Affected products
- Schneider Electric Ecostruxure Automation Expert: before 25.0.1 (fixed in 25.0.1)
Published 2026-03-10. Last modified 2026-06-23.