Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 17 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML External Entity Disclosure in EBO TGML Upload |
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Schneider-electric
Schneider-electric ecostruxure Building Operation Webstation Schneider-electric ecostruxure Building Operation Workstation |
|
| Vendors & Products |
Schneider-electric
Schneider-electric ecostruxure Building Operation Webstation Schneider-electric ecostruxure Building Operation Workstation |
Wed, 11 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files, interaction within the EBO system, or denial of service conditions when a local user uploads a specially crafted TGML graphics file to the EBO server from Workstation. | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2026-02-11T14:08:24.750Z
Reserved: 2026-01-20T12:38:23.080Z
Link: CVE-2026-1227
Updated: 2026-02-11T14:08:18.228Z
Status : Deferred
Published: 2026-02-11T14:16:02.117
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-1227
No data.
OpenCVE Enrichment
Updated: 2026-04-17T20:30:15Z