CVE-2026-8045
MEDIUM WAF: High
CVSS 6.5
Published: 2026-06-09
CWE-611
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.
WAF Coverage Analysis
XML External Entity (XXE)
High WAF Coverage
OWASP: A05:2021 Security Misconfiguration
941xxx - XSS / XXE
Affected Software
| Vendor | Product | Version |
|---|---|---|
| schneider-electric | struxureware_data_center_expert | up to 9.1.2 |
References
- download.schneider-electric.com (Vendor Advisory)