CVE-2026-8045

Severity CVSS v4.0:
HIGH
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
09/06/2026
Last modified:
20/07/2026

Description

CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schneider-electric:struxureware_data_center_expert:*:*:*:*:*:*:*:* 9.1.2 (excluding)