CVE-2026-9717 Details
Description
CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service.
A command injection vulnerability has been identified in the Schneider Electric PowerLogic P7 protection and control platform, affecting versions through V02.003.001.000. This vulnerability allows unauthorized execution of commands with elevated privileges when a privileged authenticated user interacts with a vulnerable network-exposed service. The issue could impact system integrity, confidentiality, and availability.
Users can upgrade to PowerLogic P7 version V02.004.001.000, which includes a fix for this vulnerability. This version is available through the Schneider Electric Customer Care Center. After updating, a reboot is required. If the update cannot be applied, it is recommended to restrict network access to PowerLogic P7 service endpoints on TCP/IP port 8080 and to limit administrative access, applying least privilege principles for all users.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-03.pdf | [email protected] | Vendor AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| schneider-electric powerlogic p7 firmware | < 02.004.001.000 |
CPE
Remediation
| |
| schneider-electric powerlogic p7 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |