VORANT. Threat Intelligence Sign in Get the full feed

Schneider EcoStruxure Admin Expert security bypass flaw

medium vulnerability energymanufacturinginfrastructure

A vulnerability in Schneider Electric EcoStruxure Cybersecurity Admin Expert (≤4.2.0) allows an attacker to bypass security policy enforcement.

ANSSI (CERT-FR) issued an advisory covering a vulnerability in Schneider Electric's EcoStruxure Cybersecurity Admin Expert, affecting all versions up to and including 4.2.0. The flaw, tracked as CVE-2026-14354, allows an attacker to circumvent the product's security policy controls, which could undermine centralized security management for industrial environments relying on this tool.

Schneider Electric published a corresponding security bulletin (SEVD-2026-195-02) on July 14, 2026, detailing the issue and providing remediation guidance. Organizations using affected versions of EcoStruxure Cybersecurity Admin Expert should apply the vendor's patches or mitigations promptly, as this product is typically deployed in operational technology and critical infrastructure settings where security policy integrity is essential.

Mentioned in this report

Vulnerabilities CVE-2026-14354

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0881

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free