Medium severity6.5NVD Advisory· Published Mar 10, 2026· Updated Jun 24, 2026
CVE-2026-1286
CVE-2026-1286
Description
CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file.
Affected products
3- Range: Versions prior to CS8.1
- cpe:2.3:a:schneider-electric:ecostruxure_foxboro_dcs_control_software:*:*:*:*:*:*:*:*Range: <8.1
Patches
Vulnerability mechanics
References
1- download.schneider-electric.com/filesnvdVendor AdvisoryMitigation
News mentions
0No linked articles in our index yet.