CVE-2026-19233
—Privileged-account SSRF enabling command execution in Schneider Electric product
CVE-2026-19233 is a server-side request forgery (SSRF, CWE-918) flaw in a Schneider Electric product, assigned by Schneider Electric's CNA. An attacker who already holds a privileged account sends crafted, unvalidated parameters to a server endpoint, causing the server to make unintended requests. Successful exploitation can lead to unauthorized command execution and disclosure of server data, reflected in the CVSS 4.0 score of 8.6 (High) with high impacts to confidentiality, integrity, and availability on the vulnerable system. Because the advisory data does not name the specific product or version range, affected deployments should be identified via the vendor's security notification. Exploitation status: the flaw is not listed in CISA KEV, and no public proof-of-concept or in-the-wild exploitation is known.
What to do: Identify the affected Schneider Electric product from the vendor's security notification (SEVD) and apply the patched version it specifies once applicability is confirmed; no fixed versions are given in the current data. In the interim, restrict privileged accounts on the affected system, validate or allowlist the parameters passed to the server endpoint that trigger outbound requests, and monitor for unexpected outbound connections or command execution. Since exploitation requires a privileged account, review whether privileged credentials for the product could be exposed or reused.
| Schneider Electric | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server endpoint.
- Weakness
- CWE-918
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.