CVE-2026-6866: Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel Server
CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6866?
CVE-2026-6866 has a medium severity rating due to the potential for unauthorized disclosure of sensitive information.
How do I fix CVE-2026-6866?
To fix CVE-2026-6866, update the EcoStruxure Panel Server to the latest version provided by Schneider Electric.
What types of systems are affected by CVE-2026-6866?
CVE-2026-6866 affects the Schneider Electric EcoStruxure Panel Server.
What can happen if CVE-2026-6866 is exploited?
If exploited, CVE-2026-6866 could lead to unauthorized access and disclosure of sensitive information due to credentials reverting to their default values.
Is there a known workaround for CVE-2026-6866?
Currently, there are no recommended workarounds for CVE-2026-6866 other than applying the official update.