Junglewise Threat Intelligence

CVE-2026-2273: Schneider Electric EcoStruxure Automation Expert code injection

CVE-2026-2273 · Severity: high · CVSS 8.2 · Published 2026-03-10

Vendors: Schneider Electric.

Executive brief

A vulnerability in Schneider Electric's EcoStruxure Automation Expert could allow an attacker to take control of an engineering workstation. This occurs when a user is tricked into opening a specially crafted, malicious project file. Successful exploitation could lead to unauthorized access to sensitive industrial control data or disruption of automated systems managed by the workstation.

Technical details

A code injection vulnerability (CWE-94) exists in Schneider Electric EcoStruxure Automation Expert due to improper control of code generation. The flaw is triggered when an authenticated user opens a maliciously crafted project file, leading to the execution of arbitrary commands on the local engineering workstation. This local attack requires user interaction but can result in a full compromise of the workstation's integrity and availability, potentially impacting connected industrial systems. The vulnerability is addressed in version 25.0.1.

Affected products

  • Schneider Electric EcoStruxure Automation Expert Versions prior to v25.0.1

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: advisory
  • 2026-06-23: other: NVD analysis updated

References