CVE-2026-8045EPSS p14.3%

CVE-2026-8045CVE-2026-8045

schneider-electric / struxureware_data_center_expert

Description

CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.

Scoring

CVSS 6.5 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS0.23% probability of exploitation · percentile 14.3% · 2026-08-03T12:00:16Z
Last modified2026-07-20

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-23899
CVE
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
CVE
CVE-2026-6356
CVE
CVE-2026-42924
CVE
CVE-2026-8046
CVE
CVE-2025-10713
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.