CVE-2026-8044
—Argument Injection RCE in Schneider Electric Product via Backup Configuration
CVE-2026-8044 is an argument injection flaw (CWE-88) in which argument delimiters in backup configuration parameters are not properly neutralized, allowing an attacker to inject malicious arguments. It is exploited over the network (AV:N) but requires the attacker to already hold a privileged account on the affected system, and successful exploitation can result in full remote code execution with high impact to confidentiality, integrity, and availability on the vulnerable system. The provided data does not name the specific Schneider Electric product or affected version ranges, so defenders should consult the Schneider Electric advisory for this CVE to identify their deployments. There are no reports of public proof-of-concept code, and the flaw is not currently listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Monitor Schneider Electric's security notification for CVE-2026-8044 and apply the patched release it specifies as soon as it is available. Until then, restrict privileged/administrative access to affected deployments to trusted users on management networks, and review recent backup-configuration parameter changes for unexpected values or signs of tampering.
| Schneider Electric Specific product not identified in the provided data (CNA: [email protected]; see vendor advisory for CVE-2026-8044) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as backup configuration parameters.
- Weakness
- CWE-88
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.