Junglewise Threat Intelligence

CVE-2025-11739: Schneider Electric EcoStruxure Power products unsafe deserialization

CVE-2025-11739 · Severity: high · CVSS 7.8 · Published 2026-03-10

Vendors: Schneider Electric.

Executive brief

Schneider Electric EcoStruxure Power Monitoring Expert and Power Operation are software solutions used to manage and analyze power distribution systems in industrial and commercial facilities. A security vulnerability has been identified that could allow a person with existing low-level access to the system to take full control of the software with administrative privileges. This could lead to unauthorized changes in power monitoring data or disruption of energy management operations.

Technical details

A Deserialization of Untrusted Data vulnerability (CWE-502) exists in Schneider Electric EcoStruxure Power Monitoring Expert and EcoStruxure Power Operation. The flaw is triggered when the application processes a specially crafted data stream without sufficient validation, leading to unsafe deserialization. An attacker must be locally authenticated with low-level privileges to exploit this vulnerability. Successful exploitation allows for arbitrary code execution with administrative privileges on the underlying system. Schneider Electric has released a vendor advisory (SEVD-2026-069-06) regarding this issue.

Affected products

  • Schneider Electric EcoStruxure Power Monitoring Expert (PME) 2022, 2023, 2023 R2, 2024, 2024 R2
  • Schneider Electric EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module 2022, 2024

Timeline

  • 2026-03-10: advisory: Initial advisory published by Schneider Electric
  • 2026-03-10: disclosed: CVE-2025-11739 published to NVD

References