Improper Code Control Vulnerability in Schneider Electric's Graphic Processing Application
CVE-2026-1226
7HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 11 February 2026
What is CVE-2026-1226?
An improper control of code generation vulnerability exists within Schneider Electric's TGML graphics processing application. This flaw could allow the execution of untrusted or unintended code when maliciously crafted design content is processed, potentially compromising the integrity and security of the application.
Affected Version(s)
EcoStruxure Building Operation Webstation All 6.0.x versions prior to 6.0.4.7000 (CP5)
EcoStruxure Building Operation Workstation All 7.0.x versions prior to 7.0.2