CVE-2026-8044: Schneider Electric Ecostruxure It Data Center Expert Formerly Known As Struxureware Data Center Expert
High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.
CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as backup configuration parameters.
Affected products
- Schneider Electric Ecostruxure It Data Center Expert Formerly Known As Struxureware Data Center Expert: up to and including 9.1.2
Published 2026-09-09. Last modified 2026-09-09.