CISA flags EcoStruxure DCE CVE-2026-8045 file-read flaw
Authenticated-only access keeps this below panic territory, but compromised accounts still turn monitoring software into a configuration-file scavenger.
TL;DR
CISA disclosed CVE-2026-8045, a CVSS 6.5 XML external entity flaw in Schneider Electric EcoStruxure IT Data Center Expert v9.1.1 and earlier. An attacker with a Data Center Expert user account can submit crafted XML payloads to SOAP service endpoints and read server-side file contents. Contractors running the software should move to v9.1.2 and treat delay as extra reconnaissance time in IT and OT environments.
CISA’s advisory is a patch item, not a fire drill. Schneider Electric EcoStruxure IT Data Center Expert v9.1.1 and earlier contain an XML external entity vulnerability, CVE-2026-8045, that can disclose server-side file contents when an attacker already has a Data Center Expert user account and sends crafted XML payloads to SOAP service endpoints.
The practical risk is narrower than the usual high-severity industrial control system advisory: CVSS 6.5, low privileges required, no user interaction, confidentiality impact high, integrity and availability impact none. That still matters for defense-industrial-base and contractor environments where data center monitoring systems can hold useful configuration material. Patch to v9.1.2, verify whether the upgrade is actually deployed at customer sites, and do not assume CISA’s notice means active exploitation has been seen. The advisory does not say that.
Published ·Deep Fathom