Skip to content
CodeAuditAgent

CVE-2026-6866

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.

Weakness

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.

Affected products

  • schneider-electric ecostruxure_panel_server_pas400_firmware
  • schneider-electric ecostruxure_panel_server_pas400
  • schneider-electric ecostruxure_panel_server_pas600_firmware
  • schneider-electric ecostruxure_panel_server_pas600
  • schneider-electric ecostruxure_panel_server_pas600v2_firmware
  • schneider-electric ecostruxure_panel_server_pas600v2
  • schneider-electric ecostruxure_panel_server_pas800_firmware
  • schneider-electric ecostruxure_panel_server_pas800

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.