PT-2026-40037 · Schneider Electric · Ecostruxure Panel Server+5

CVE-2026-6866

·

Published

2026-05-12

·

Updated

2026-06-11

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Schneider Electric EcoStruxure Panel Server (affected versions not specified)
Description An insecure default resource initialization issue exists that may cause credentials to revert to initial settings under rare circumstances. This allows unauthorized authentication using known credentials, potentially leading to the unauthorized disclosure of sensitive information. Real-world incidents have been observed where attackers gained administrative control and performed lateral movement across connected Operational Technology (OT) systems following the initial compromise.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Implement runtime segmentation to contain post-compromise activity within critical infrastructure networks.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6866

Affected Products

Ecostruxure Panel Server
Ecostruxure Panel Server Pas400 Firmware
Ecostruxure Panel Server Pas600 Firmware
Ecostruxure Panel Server Pas600V2 Firmware
Ecostruxure Panel Server Pas800 Firmware
Ecostruxure Panel Server Pas800V2 Firmware