CVE-2026-8045: XEE
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8045?
CVE-2026-8045 has a severity rating of high, with a CVSS score of 7.1.
How do I fix CVE-2026-8045?
To mitigate CVE-2026-8045, ensure that your instance of Schneider-electric Struxureware Data Center Expert is updated to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-8045?
CVE-2026-8045 is classified as an Improper Restriction of XML External Entity Reference vulnerability.
What can an attacker do with CVE-2026-8045?
An attacker with a Data Center Expert user account can submit crafted XML payloads to disclose sensitive server-side file contents.
Which software is affected by CVE-2026-8045?
The affected software for CVE-2026-8045 is Schneider-electric Struxureware Data Center Expert.