Description
CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker leverages weaknesses in the handling and protection of stored credentials within the application.
Published: 2026-07-29
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an insufficiently protected credentials flaw that allows a local privileged attacker to bypass authentication and alter stored credentials within the EcoStruxure Cybersecurity Admin Expert application. This flaw could enable the attacker to assume higher privileges, gain control over managed devices, and potentially carry out further malicious operations. The weakness is classified as CWE‑522.

Affected Systems

Schneider Electric EcoStruxure Cybersecurity Admin Expert is affected. No specific product versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a local privileged user who can execute the flaw to modify credentials and bypass authentication, given the local nature of the weakness described.

Generated by OpenCVE AI on August 4, 2026 at 12:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade EcoStruxure Cybersecurity Admin Expert to a version that protects stored credentials according to CWE‑522 best practices
  • Configure the system to store credentials using strong encryption or key management, ensuring that they are not retained in plaintext
  • Restrict local privileged access by disabling unnecessary local management interfaces or enforcing strict local admin account policies

Generated by OpenCVE AI on August 4, 2026 at 12:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Title Insufficiently Protected Credentials Leading to Authentication Bypass in Schneider Electric EcoStruxure Cybersecurity Admin Expert

Sat, 01 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Insufficiently Protected Credentials Leading to Authentication Bypass in Schneider Electric EcoStruxure Cybersecurity Admin Expert

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Schneider-electric
Schneider-electric ecostruxure Cybersecurity Admin Expert
Vendors & Products Schneider-electric
Schneider-electric ecostruxure Cybersecurity Admin Expert

Wed, 29 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker leverages weaknesses in the handling and protection of stored credentials within the application.
Weaknesses CWE-522
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Schneider-electric Ecostruxure Cybersecurity Admin Expert
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2026-07-29T12:42:22.173Z

Reserved: 2026-07-01T17:31:38.767Z

Link: CVE-2026-14354

cve-icon Vulnrichment

Updated: 2026-07-29T12:42:18.626Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-29T13:17:42.723

Modified: 2026-07-30T16:43:03.817

Link: CVE-2026-14354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:45:05Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials