Junglewise Threat Intelligence

CVE-2026-9717: Schneider Electric PowerLogic P7 OS command injection

CVE-2026-9717 · Severity: info · CVSS 8.6 · Published 2026-06-25

Technologies: Schneider Electric PowerLogic P7. Vendors: Schneider Electric.

Executive brief

A security vulnerability exists in Schneider Electric PowerLogic P7 protection relays, which are used to monitor and manage electrical power systems. An attacker with high-level administrative access could execute unauthorized commands on the device's operating system. This could lead to a complete loss of control over the device, potentially disrupting power management operations or allowing unauthorized access to sensitive configuration data.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Schneider Electric PowerLogic P7 firmware. The flaw is located in a network-exposed service that fails to properly neutralize special elements used in OS commands. An attacker with high privileges (PR:H) can exploit this over the network (AV:N) without user interaction. Successful exploitation allows for unauthorized execution of commands with elevated privileges, compromising the integrity, confidentiality, and availability of the affected system. The vulnerability affects Version V02.003.001.000 and all prior versions.

Affected products

  • Schneider Electric PowerLogic™ P7 Version V02.003.001.000 and prior

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory: Advisory SEVD-2026-160-03 published by Schneider Electric

References

Related threats