Junglewise Threat Intelligence

CVE-2026-1286: Schneider Electric EcoStruxure Foxboro DCS deserialization in project files

CVE-2026-1286 · Severity: medium · CVSS 6.5 · Published 2026-03-10

Vendors: Schneider Electric.

Executive brief

A vulnerability exists in Schneider Electric's industrial control software that could allow an attacker to take control of a workstation. This occurs when a user with administrative privileges opens a specially crafted, malicious project file. If exploited, this could lead to a complete loss of data confidentiality and system integrity, potentially disrupting industrial operations.

Technical details

A CWE-502 (Deserialization of Untrusted Data) vulnerability exists in Schneider Electric EcoStruxure Foxboro DCS Control Software. The flaw is triggered when the application improperly deserializes data from a malicious project file. An attacker requires local access to provide the file, and the exploit requires a high-privileged (admin) user to interact with the file (user interaction). Successful exploitation can lead to arbitrary code execution on the workstation with the privileges of the authenticated user. The issue is addressed in version CS8.1.

Affected products

  • Schneider Electric EcoStruxure Foxboro DCS Control Software Versions prior to CS8.1

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: advisory

References