CVE-2026-6866 Details
Description
CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.
A vulnerability exists in Schneider Electric's EcoStruxure Panel Server products, specifically in versions through 002.005.000. This vulnerability, categorized as CWE-1188, involves the initialization of a resource with an insecure default, which could lead to the unauthorized disclosure of sensitive information. In rare circumstances, credentials may revert to their initial settings, allowing unauthorized authentication with known credentials.
Users can upgrade to EcoStruxure Panel Server version 002.006.000, available for download from the Schneider Electric website, to address this vulnerability. A reboot is required after the upgrade. For assistance, contact Schneider Electric's Customer Care Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-132-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-132-04.pdf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| schneider-electric ecostruxure panel server pas400 firmware | < 002.006.000 |
CPE
Remediation
| |
| schneider-electric ecostruxure panel server pas400 | All versions |
CPE
Remediation
| |
| schneider-electric ecostruxure panel server pas600 firmware | < 002.006.000 |
CPE
Remediation
| |
| schneider-electric ecostruxure panel server pas600 | All versions |
CPE
Remediation
| |
| schneider-electric ecostruxure panel server pas600v2 firmware | < 002.006.000 |
CPE
Remediation
| |
| schneider-electric ecostruxure panel server pas600v2 | All versions |
CPE
Remediation
| |
| schneider-electric ecostruxure panel server pas800 firmware | < 002.006.000 |
CPE
Remediation
| |
| schneider-electric ecostruxure panel server pas800 | All versions |
CPE
Remediation
| |
| schneider-electric ecostruxure panel server pas800v2 firmware | < 002.006.000 |
CPE
Remediation
| |
| schneider-electric ecostruxure panel server pas800v2 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |