ZeroHour

CVE-2026-19233

Privileged-account SSRF enabling command execution in Schneider Electric product

CVSS 4.0
8.6 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-19233 is a server-side request forgery (SSRF, CWE-918) flaw in a Schneider Electric product, assigned by Schneider Electric's CNA. An attacker who already holds a privileged account sends crafted, unvalidated parameters to a server endpoint, causing the server to make unintended requests. Successful exploitation can lead to unauthorized command execution and disclosure of server data, reflected in the CVSS 4.0 score of 8.6 (High) with high impacts to confidentiality, integrity, and availability on the vulnerable system. Because the advisory data does not name the specific product or version range, affected deployments should be identified via the vendor's security notification. Exploitation status: the flaw is not listed in CISA KEV, and no public proof-of-concept or in-the-wild exploitation is known.

What to do: Identify the affected Schneider Electric product from the vendor's security notification (SEVD) and apply the patched version it specifies once applicability is confirmed; no fixed versions are given in the current data. In the interim, restrict privileged accounts on the affected system, validate or allowlist the parameters passed to the server endpoint that trigger outbound requests, and monitor for unexpected outbound connections or command execution. Since exploitation requires a privileged account, review whether privileged credentials for the product could be exposed or reused.

Affected
Schneider Electric
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server endpoint.

Weakness
CWE-918
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.