Schneider Electric EcoStruxure Building Operation Workstation and WebStation Improper XML External Entity Handling Vulnerability

Vulnerability

A vulnerability allowing improper restriction of XML external entity references has been identified in Schneider Electric's EcoStruxure Building Operation (EBO) Workstation and WebStation. This vulnerability, present in all 7.0.x versions prior to 7.0.3.2000 (CP1) and all 6.x versions prior to 6.0.4.14001 (CP10), could lead to unauthorized disclosure of local files, interaction within the EBO system, or denial-of-service conditions. The issue arises when a local user uploads a specially crafted TGML graphics file to the EBO server from Workstation.

Impact

Exploitation of this vulnerability could result in unauthorized access to local files, disruption of service, or unauthorized interactions within the EBO system.

Remediation

Users can upgrade to EcoStruxure Building Operation versions 7.0.3.2000 (CP1) or 6.0.4.14001 (CP10). Instructions for downloading the patch are available on the Schneider Electric MySchneider Documents Download Center.

Added: Feb 11, 2026, 2:22 PM
Updated: Feb 11, 2026, 5:50 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
2.6
remediation
7.9
relevance
3.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.