# Schneider EcoStruxure Admin Expert security bypass flaw

Published: 2026-07-15 · Severity: medium · Sectors: energy, manufacturing, infrastructure
Canonical: https://vorant.io/reports/fea9f1f0-4a90-5080-93c5-804929d73c35/schneider-ecostruxure-admin-expert-security-bypass-flaw

> A vulnerability in Schneider Electric EcoStruxure Cybersecurity Admin Expert (≤4.2.0) allows an attacker to bypass security policy enforcement.

ANSSI (CERT-FR) issued an advisory covering a vulnerability in Schneider Electric's EcoStruxure Cybersecurity Admin Expert, affecting all versions up to and including 4.2.0. The flaw, tracked as CVE-2026-14354, allows an attacker to circumvent the product's security policy controls, which could undermine centralized security management for industrial environments relying on this tool.

Schneider Electric published a corresponding security bulletin (SEVD-2026-195-02) on July 14, 2026, detailing the issue and providing remediation guidance. Organizations using affected versions of EcoStruxure Cybersecurity Admin Expert should apply the vendor's patches or mitigations promptly, as this product is typically deployed in operational technology and critical infrastructure settings where security policy integrity is essential.

## Mentioned in this report

- Vulnerabilities: CVE-2026-14354

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0881

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fea9f1f0-4a90-5080-93c5-804929d73c35/schneider-ecostruxure-admin-expert-security-bypass-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
