CVE-2026-2273
EUVD-2026-1057110.03.2026, 18:18
CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent system when an authenticated user opens a malicious project file.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| schneider-electric | ecostruxure_automation_expert | 𝑥 < 25.0.1 |
𝑥
= Vulnerable software versions