download.schneider-electric.com
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-069-04.pdf CVE-2026-2273
HIGH
EcoStruxure Automation Expert Code Injection via Malicious Project File
Record summary
CVE-2026-2273 has a selected CVSS score of 7.2 (high).
Description
CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent system when an authenticated user opens a malicious project file.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
EcoStruxure™ Automation ExpertBrowse Schneider Electric / EcoStruxure™ Automation ExpertDefault status: unaffected | CVE List | Versions prior to v25.0.1 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-2273