CVE-2026-13336
—OS Command Injection via Malicious Backup Restore in Schneider Electric Product
CVE-2026-13336 is an OS command injection flaw (CWE-78) in the backup/restore functionality of an affected Schneider Electric product, assigned by Schneider Electric's CNA. It is triggered when an administrator restores a system backup file that has been maliciously modified, causing arbitrary Linux operating system commands to be executed on the device during the restore. Because the CVSS 4.0 vector requires high privileges (PR:H), an adjacent network position (AV:A), and specialized attack conditions (AT:P), exploitation most plausibly requires an attacker who can tamper with a backup file or its storage location, such as an insider or an attacker with access to the network path or backup repository. Successful exploitation yields high impact to confidentiality, integrity, and availability on the vulnerable system (VC:H/VI:H/VA:H), effectively full command execution on the underlying Linux OS. As of this analysis there is no known exploitation, no public proof-of-concept, it is not in the CISA KEV catalog, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days.
What to do: Monitor Schneider Electric's security notifications (SEVD) referenced by this CVE and apply the patched firmware or software version once identified in the vendor advisory. Until patched, only restore backups from trusted sources, verify the integrity of backup files (e.g., checksums) before restoring, and restrict access to backup storage and administrative/restore interfaces on the affected device. Given the AV:A attack vector, segment administrative access to the device from untrusted adjacent networks.
| Schneider Electric | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands when a system back up is restored that has been maliciously modified.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.