XXE Vulnerability in Schneider Electric EcoStruxure Exposes Server-Side Files
A XML External Entity (XXE) injection vulnerability (CVE-2026-8045, CWE-611) in Schneider Electric's EcoStruxure IT Data Center Expert allows any authenticated user to craft malicious XML payloads that trick the server into disclosing sensitive file contents. This is particularly dangerous in industrial and data center environments where the software manages critical infrastructure, meaning exposed configuration files could reveal credentials, network topology, or other sensitive operational data. The vulnerability exists in versions prior to 9.1.2, and a patch is already available, making delayed remediation unjustifiable. XXE vulnerabilities are a well-understood and preventable class of flaw, highlighting a gap in secure development practices and XML parser hardening within the product. Organizations running unpatched versions remain exposed to insider threats or attackers who have obtained any level of user account access.
Tactical Insight
Immediate Actions
- Upgrade all instances of EcoStruxure IT Data Center Expert to version 9.1.2 or later without delay.
- Audit current user accounts with access to the platform and revoke any unnecessary or stale credentials.
- Restrict network access to the EcoStruxure management interface to trusted hosts and management VLANs only.
Long-Term Improvements
- Enforce XML parser hardening across all enterprise applications by disabling external entity processing by default.
- Integrate ICS/SCADA and OT software into your standard vulnerability management and patch lifecycle program.
- Maintain a current software inventory (SBOM) for all operational technology and infrastructure management tools to enable rapid impact assessment during disclosures.
Detection Measures
- Monitor application and server logs for anomalous XML submissions or unexpected outbound file-read activity.
- Deploy a Web Application Firewall (WAF) or IDS rule set to detect and alert on XXE payload patterns targeting management interfaces.
- Establish alerting for any privilege escalation or unusual data access patterns by authenticated users within critical infrastructure platforms.