Executive brief
A server-side request forgery (SSRF) vulnerability exists in a Schneider Electric server endpoint that could allow a privileged account holder to execute unauthorized commands and access sensitive server data. An attacker with legitimate administrative credentials can craft malicious requests to bypass security controls and compromise the integrity and confidentiality of the system.
Technical details
This is a server-side request forgery (SSRF) vulnerability (CWE-918) in a Schneider Electric server endpoint. The vulnerability arises from insufficient validation of user-supplied parameters passed to a server endpoint, allowing an authenticated attacker with privileged account access to craft specially-crafted requests that force the server to perform unintended actions. An attacker with a privileged account can exploit this to execute arbitrary commands on the server and disclose confidential server data. This vulnerability requires authentication and privileged account status, limiting exposure to insider threats or compromised administrative credentials.
Affected products
- Schneider Electric <UNKNOWN>
Timeline
- 2026-09-09: disclosed