CVE-2026-6866 PUBLISHED

Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel Server

Assigner: schneider
Reserved: 22.04.2026 Published: 12.05.2026 Updated: 12.05.2026

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.2

Product Status

Vendor Schneider Electric
Product EcoStruxure™ Panel Server
Versions Default: unaffected
  • Version Versions 002.005.000 and prior is affected

References

Problem Types

  • CWE-1188 Initialization of a resource with an insecure default CWE