CVE-2026-6866EPSS p21.5%

CVE-2026-6866CVE-2026-6866

schneider-electric / ecostruxure_panel_server_pas400_firmware

Description

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.

Scoring

CVSS 7.5 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS0.29% probability of exploitation · percentile 21.5% · 2026-08-11T12:00:17Z
Last modified2026-06-24
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.