CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server endpoint.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 09 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SSRF Vulnerability Allowing Unauthorized Command Execution in Schneider Electric EcoStruxure IT Data Center Expert |
Wed, 09 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server endpoint. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2026-09-09T16:29:49.130Z
Reserved: 2026-08-07T11:17:36.057Z
Link: CVE-2026-19233
No data.
Status : Received
Published: 2026-09-09T17:17:17.783
Modified: 2026-09-09T17:17:17.783
Link: CVE-2026-19233
No data.
OpenCVE Enrichment
Updated: 2026-09-09T17:30:07Z
Weaknesses