CVE-2026-1286

CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:schneider-electric:ecostruxure_foxboro_dcs_control_software:*:*:*:*:*:*:*:*

History

24 Jun 2026, 15:36

Type Values Removed Values Added
First Time Schneider-electric
Schneider-electric ecostruxure Foxboro Dcs Control Software
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-069-03.pdf - () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-069-03.pdf - Vendor Advisory, Mitigation
CPE cpe:2.3:a:schneider-electric:ecostruxure_foxboro_dcs_control_software:*:*:*:*:*:*:*:*

17 Jun 2026, 10:15

Type Values Removed Values Added
Summary
  • (es) CWE-502: Existe una vulnerabilidad de deserialización de datos no confiables que podría conducir a la pérdida de confidencialidad, integridad y una posible ejecución remota de código en la estación de trabajo cuando un usuario autenticado como administrador abre un archivo de proyecto malicioso.

10 Mar 2026, 18:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 18:18

Updated : 2026-06-24 15:36


NVD link : CVE-2026-1286

Mitre link : CVE-2026-1286

CVE.ORG link : CVE-2026-1286


JSON object : View

Products Affected

schneider-electric

  • ecostruxure_foxboro_dcs_control_software
CWE
CWE-502

Deserialization of Untrusted Data