CVE-2026-9717 PUBLISHED

Assigner: schneider
Reserved: 27.05.2026 Published: 25.06.2026 Updated: 25.06.2026

CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor Schneider Electric
Product PowerLogic™ P7
Versions Default: unaffected
  • Version Version V02.003.001.000 and prior is affected

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE