CVE-2026-8044: Schneider Electric Ecostruxure It Data Center Expert Formerly Known As Struxureware Data Center Expert

High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as backup configuration parameters.

Affected products

  • Schneider Electric Ecostruxure It Data Center Expert Formerly Known As Struxureware Data Center Expert: up to and including 9.1.2

Published 2026-09-09. Last modified 2026-09-09.