PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-6866 Schneider Electric CVE debrief

CVE-2026-6866 is a CWE-1188 Initialization of a Resource with an Insecure Default vulnerability in Schneider Electric's EcoStruxure Panel Server. The vulnerability has a CVSS v4.0 Base Score of 7.5 and could cause unauthorized disclosure of sensitive information when credentials revert to initial settings. This vulnerability exists in multiple versions of the EcoStruxure Panel Server, including PAS800, PAS800V2, PAS600, PAS600V2, and PAS400. Schneider Electric has released patches for this vulnerability, which can be downloaded from their website.

Vendor
Schneider Electric
Product
EcoStruxure Panel Server PAS800
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-06-09
Advisory published
2026-05-12
Advisory updated
2026-06-09

Who should care

Organizations using Schneider Electric's EcoStruxure Panel Server, particularly those in industrial control systems (ICS) environments, should be aware of this vulnerability. The vulnerability's high CVSS score and potential impact on sensitive information disclosure make it a priority for defenders to assess their inventory and apply patches or mitigations as needed.

Technical summary

The CWE-1188 Initialization of a Resource with an Insecure Default vulnerability in Schneider Electric's EcoStruxure Panel Server could allow unauthorized authentication using known credentials. The vulnerability has a CVSS v4.0 Base Score of 7.5 and is considered high-severity. Multiple products are affected, including PAS800, PAS800V2, PAS600, PAS600V2, and PAS400. Schneider Electric has released patches for this vulnerability, which involve updating to version 002.006.000 or later.

Defensive priority

Defenders should prioritize patching affected EcoStruxure Panel Server systems, as the vulnerability has a high CVSS score and could lead to unauthorized disclosure of sensitive information. Additionally, defenders should review their inventory to ensure all affected products are identified and patched.

Recommended defensive actions

  • Apply patches for affected EcoStruxure Panel Server systems
  • Review inventory to ensure all affected products are identified
  • Implement compensating controls, such as network segmentation and access controls
  • Monitor for suspicious activity related to the vulnerability
  • Consider implementing additional security measures, such as multi-factor authentication

Evidence notes

The CVE-2026-6866 vulnerability is documented in the CISA CSAF file and Schneider Electric's security advisories. The vulnerability has a CVSS v4.0 Base Score of 7.5 and is considered high-severity. Multiple products are affected, including PAS800, PAS800V2, PAS600, PAS600V2, and PAS400.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-6866 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-6866

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-6866 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6866

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-160-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.se.com/ww/en/download/document/7EN52-0390/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-160-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.