Schneider Panel Server defaults expose credentials
Schneider Electric EcoStruxure Panel Server contains a flaw where credentials can revert to insecure defaults, enabling unauthorized authentication and access to sensitive data.
Schneider Electric has disclosed CVE-2026-6866, an initialization vulnerability in its EcoStruxure Panel Server product line that could allow unauthorized access to sensitive information. The flaw affects multiple models (PAS800, PAS800V2, PAS600, PAS600V2, and PAS400) running firmware versions 002.005.000 and prior. Under rare circumstances, credentials revert to initial default settings, enabling attackers with knowledge of these defaults to gain unauthorized authentication.
The vulnerability stems from insecure resource initialization (CWE-1188) and impacts industrial control systems deployed globally across critical infrastructure sectors including energy, critical manufacturing, and commercial facilities. Schneider Electric has released firmware version 002.006.000 to address the issue, requiring a system reboot after installation.
The disclosure was reported through Schneider Electric's CPCERT by both internal security teams and a partner organization. CISA recommends organizations isolate affected systems behind firewalls, restrict remote access to VPNs, and apply the vendor patch immediately to mitigate exploitation risk in operational technology environments.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-160-03
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free