Junglewise Threat Intelligence

CVE-2026-8045: Schneider Electric Data Center Expert XXE in SOAP service

CVE-2026-8045 · Severity: info · CVSS 7.1 · Published 2026-06-09

Vendors: Schneider Electric.

Executive brief

Schneider Electric Data Center Expert is a management platform used to monitor and manage physical infrastructure in data centers. A security vulnerability in this system allows an authorized user to upload specially crafted files that trick the server into revealing sensitive internal files. This could lead to the exposure of confidential system information or configuration data, potentially aiding further attacks on the infrastructure.

Technical details

An Improper Restriction of XML External Entity Reference (XXE) vulnerability (CWE-611) exists within the SOAP service endpoints of Schneider Electric Data Center Expert. The vulnerability is rooted in the XML parser's failure to disable external entity resolution when processing SOAP requests. An attacker with valid 'Data Center Expert' user credentials can submit a crafted XML payload containing malicious external entity references. If successful, the attacker can read arbitrary files from the server's filesystem, leading to unauthorized information disclosure. The vulnerability is reachable over the network but requires low-privileged authentication.

Affected products

  • Schneider Electric Data Center Expert

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Advisory SEVD-2026-160-01 published by Schneider Electric

References