Schneider EcoStruxure Data Center Expert confidentiality flaw
A vulnerability in Schneider Electric EcoStruxure IT Data Center Expert versions before 9.1.2 allows attackers to compromise data confidentiality.
Schneider Electric has disclosed a security vulnerability affecting EcoStruxure IT Data Center Expert, a data center infrastructure management platform. The flaw, tracked as CVE-2026-8045, impacts all versions prior to 9.1.2 and enables unauthorized access to sensitive data. The vulnerability represents a confidentiality risk for organizations using the affected software to manage their data center operations.
Schneider Electric has released version 9.1.2 to address this issue. Organizations running earlier versions of EcoStruxure IT Data Center Expert should prioritize patching to prevent potential data exposure. The advisory was published by France's ANSSI (Agence nationale de la sécurité des systèmes d'information) on June 9, 2026.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0713
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free