CVE-2026-6865
View CSAF Summary Successful exploitation this vulnerability could allow an attacker to gain unauthorized access to sensitive files The following versions of Schneider Electric EasyLogic T150 and S...
Affects 0 products across 4 vendors.
Attacker manipulates file path inputs to access files outside the intended directory.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A Path Traversal vulnerability (CWE-22) exists in the server-side file path processing, which could allow unauthorized access to sensitive files if user-supplied input is not properly validated.
BSID: BS-2026-GLOBAL-154549-I • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-6865?
Is CVE-2026-6865 actively exploited?
How do I remediate CVE-2026-6865?
What systems are affected by CVE-2026-6865?
| CVE ID | CVE-2026-6865 |
|---|---|
| BSID | BS-2026-GLOBAL-154549-I BreachSpider Global ID |
| Published | 2026-06-18 |
| Last Modified | 2026-06-18 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary Successful exploitation this vulnerability could allow an attacker to gain unauthorized access to sensitive files The following versions of Schneider Electric EasyLogic T150 and Saitel DP are affected: Schneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller Firmware installed on Schneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller (All versions) vers:semver/<=11.06.31 (CVE-2026-6865) Schneider Electric Saitel
Source: NIST NVD / MITRE CVE Database
An attacker could exploit this vulnerability by manipulating file paths in requests to access files outside the intended directory, potentially leading to sensitive data exposure.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Files | — | — |
| Processing | — | — |
| Schneider-Electric | — | — |
| Wolfram Schneider | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →