Junglewise Threat Intelligence

CVE-2026-77120: Schneider Electric OS command injection in SSH console

CVE-2026-77120 · Severity: info · Published 2026-09-09

Vendors: Schneider Electric.

Executive brief

A command injection vulnerability exists in Schneider Electric operating system components when accessed via SSH console. An authenticated user can inject arbitrary operating system commands, potentially gaining root privilege escalation and executing unauthorized administrative functions. This affects systems where SSH console access is enabled.

Technical details

An OS command injection vulnerability (CWE-78) exists in the SSH console interface of Schneider Electric systems that improperly processes user-controlled input. The vulnerability requires an authenticated user with SSH access to the operating system console. An attacker can inject special characters and OS commands through console input to achieve privilege escalation to root and execute arbitrary administrative functions. The attack is feasible only when SSH is enabled on the affected system.

Affected products

  • Schneider Electric <UNKNOWN>

Timeline

  • 2026-09-09: disclosed

References