PatchSiren cyber security CVE debrief
CVE-2026-6866 Schneider Electric CVE debrief
CVE-2026-6866 is a CWE-1188 Initialization of a Resource with an Insecure Default vulnerability in Schneider Electric's EcoStruxure Panel Server. The vulnerability has a CVSS v4.0 Base Score of 7.5 and could cause unauthorized disclosure of sensitive information when credentials revert to initial settings. This vulnerability exists in multiple versions of the EcoStruxure Panel Server, including PAS800, PAS800V2, PAS600, PAS600V2, and PAS400. Schneider Electric has released patches for this vulnerability, which can be downloaded from their website.
- Vendor
- Schneider Electric
- Product
- EcoStruxure Panel Server PAS800
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-06-09
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-06-09
Who should care
Organizations using Schneider Electric's EcoStruxure Panel Server, particularly those in industrial control systems (ICS) environments, should be aware of this vulnerability. The vulnerability's high CVSS score and potential impact on sensitive information disclosure make it a priority for defenders to assess their inventory and apply patches or mitigations as needed.
Technical summary
The CWE-1188 Initialization of a Resource with an Insecure Default vulnerability in Schneider Electric's EcoStruxure Panel Server could allow unauthorized authentication using known credentials. The vulnerability has a CVSS v4.0 Base Score of 7.5 and is considered high-severity. Multiple products are affected, including PAS800, PAS800V2, PAS600, PAS600V2, and PAS400. Schneider Electric has released patches for this vulnerability, which involve updating to version 002.006.000 or later.
Defensive priority
Defenders should prioritize patching affected EcoStruxure Panel Server systems, as the vulnerability has a high CVSS score and could lead to unauthorized disclosure of sensitive information. Additionally, defenders should review their inventory to ensure all affected products are identified and patched.
Recommended defensive actions
- Apply patches for affected EcoStruxure Panel Server systems
- Review inventory to ensure all affected products are identified
- Implement compensating controls, such as network segmentation and access controls
- Monitor for suspicious activity related to the vulnerability
- Consider implementing additional security measures, such as multi-factor authentication
Evidence notes
The CVE-2026-6866 vulnerability is documented in the CISA CSAF file and Schneider Electric's security advisories. The vulnerability has a CVSS v4.0 Base Score of 7.5 and is considered high-severity. Multiple products are affected, including PAS800, PAS800V2, PAS600, PAS600V2, and PAS400.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6866 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6866
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6866 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6866
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-160-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/ww/en/download/document/7EN52-0390/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-160-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.