CVE-2026-6866

HIGH

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in ...

Affects 0 products across 2 vendors.

BCS3.87
CVSS 3.17.5
CVSS v48.2
EPSS0.3%
Percentile21th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, no integrity impact, no availability impact.
CWE Weakness Definitions
CWE-1188: CWE-1188
Related Attack Patterns (CAPEC)
CAPEC-665 Exploitation of Thunderbolt Protection Flaws
via CWE-1188

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability exists where resources are initialized with insecure default settings, potentially leading to unauthorized disclosure of sensitive information and unauthorized authentication.

BSID: BS-2026-GLOBAL-154550-I • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-6866?
A vulnerability exists where resources are initialized with insecure default settings, potentially leading to unauthorized disclosure of sensitive information and unauthorized authentication.
What is the CVSS score for CVE-2026-6866?
CVE-2026-6866 has CVSS 7.5 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. EPSS: 0.3%.
Is CVE-2026-6866 actively exploited?
No confirmed active exploitation of CVE-2026-6866 as of 2026-06-25.
How do I remediate CVE-2026-6866?
Priority: HIGH.
What systems are affected by CVE-2026-6866?
CVE-2026-6866 affects: Schneider-Electric, Wolfram Schneider.
Vulnerability Details
CVE IDCVE-2026-6866
BSIDBS-2026-GLOBAL-154550-I BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published2026-05-12
Last Modified2026-06-24
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises when system credentials revert to default settings under rare circumstances, allowing attackers to use known default credentials to gain unauthorized access.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Schneider-Electric —
Wolfram Schneider —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 74 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
Related CVEs affecting Schneider-Electric
CVE-2011-4861 10.0 The modbus_125_handler function in the Schneider Electric Quantum Ethernet Mo... CVE-2013-0657 10.0 Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA... CVE-2020-11897 10.0 The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multipl... CVE-2020-11896 10.0 The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related ... CVE-2013-3075 10.0 Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3...
View all Schneider-Electric CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →