Schneider Electric EcoStruxure Building Operation Workstation and WebStation Improper Control of Code Generation Vulnerability

Vulnerability

A vulnerability allowing the execution of untrusted or unintended code has been identified in Schneider Electric's EcoStruxure Building Operation Workstation and WebStation. This issue arises from improper control in the generation of code, specifically when maliciously crafted design content is processed through a TGML graphics file. The vulnerability affects all 7.0.x versions prior to 7.0.2, as well as all 6.0.x versions prior to 6.0.4.7000 (CP5) and all 6.x versions prior to 6.0.4.14001 (CP10).

Impact

Exploitation of this vulnerability could lead to the execution of untrusted or unintended code within the application.

Remediation

Users can upgrade to EcoStruxure Building Operation versions 7.0.2 or 6.0.4.7000 (CP5) or 6.0.4.14001 (CP10). Instructions for downloading the patch are available on the Schneider Electric MySchneider Documents Download Center.

Added: Feb 11, 2026, 2:17 PM
Updated: Feb 11, 2026, 5:58 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
3.0
remediation
7.9
relevance
2.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.