High severity7.2NVD Advisory· Published Jun 25, 2026· Updated Jul 1, 2026
CVE-2026-9717
CVE-2026-9717
Description
CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service.
Affected products
2- cpe:2.3:o:schneider-electric:powerlogic_p7_firmware:*:*:*:*:*:*:*:*Range: <02.004.001.000
Patches
Vulnerability mechanics
References
1- download.schneider-electric.com/filesnvdVendor AdvisoryMitigation
News mentions
1- Schneider Electric PowerLogic P7CISA ICS Advisories