Improper XML External Entity Handling in Schneider Electric EBO Software
CVE-2026-1227
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 11 February 2026
What is CVE-2026-1227?
A vulnerability exists in Schneider Electric's EBO software that improperly restricts XML External Entity (XXE) references. An attacker can exploit this flaw by uploading a specially crafted TGML graphics file, potentially leading to unauthorized access to local files and interaction with the EBO system. This exploitation could manifest in significant disruptions, including denial of service conditions. It's crucial for users to implement appropriate security measures to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EcoStruxure Building Operation Webstation All 6.x versions prior to 6.0.4.14001 (CP10)
EcoStruxure Building Operation Workstation All 7.0.x versions prior to 7.0.3.2000 (CP1)
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved