Junglewise Threat Intelligence

CVE-2026-6865: Schneider Electric path traversal in server-side file processing

CVE-2026-6865 · Severity: info · CVSS 7.1 · Published 2026-05-12

Vendors: Schneider Electric.

Executive brief

A path traversal vulnerability has been identified in a Schneider Electric product. This flaw allows an authenticated user to bypass security restrictions and access sensitive files stored on the system. Such an exploit could lead to the exposure of confidential configuration data or system credentials, potentially compromising the integrity of industrial operations.

Technical details

A path traversal vulnerability (CWE-22) exists in a Schneider Electric component due to improper limitation of user-supplied input during server-side file path processing. An attacker with low-level authenticated access can exploit this by submitting specially crafted requests containing directory traversal sequences (e.g., ../). Successful exploitation allows the attacker to read sensitive files outside of the intended directory and potentially modify certain files, as indicated by the CVSS VI:L (Low Integrity impact) rating. The vulnerability is reachable over the network and does not require user interaction.

Affected products

  • Schneider Electric Unknown Product

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Advisory SEVD-2026-132-03 published by Schneider Electric

References