ZeroHour

CVE-2026-8044

Argument Injection RCE in Schneider Electric Product via Backup Configuration

CVSS 4.0
8.6 high
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-8044 is an argument injection flaw (CWE-88) in which argument delimiters in backup configuration parameters are not properly neutralized, allowing an attacker to inject malicious arguments. It is exploited over the network (AV:N) but requires the attacker to already hold a privileged account on the affected system, and successful exploitation can result in full remote code execution with high impact to confidentiality, integrity, and availability on the vulnerable system. The provided data does not name the specific Schneider Electric product or affected version ranges, so defenders should consult the Schneider Electric advisory for this CVE to identify their deployments. There are no reports of public proof-of-concept code, and the flaw is not currently listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Monitor Schneider Electric's security notification for CVE-2026-8044 and apply the patched release it specifies as soon as it is available. Until then, restrict privileged/administrative access to affected deployments to trusted users on management networks, and review recent backup-configuration parameter changes for unexpected values or signs of tampering.

Affected
Schneider Electric Specific product not identified in the provided data (CNA: [email protected]; see vendor advisory for CVE-2026-8044)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as backup configuration parameters.

Weakness
CWE-88
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.