Schneider Electric Discloses Session-Management Flaw Across Broad OT Portfolio

A high-severity insufficient-entropy vulnerability in dozens of Schneider Electric protection relays, power automation systems, and related products could allow a network-adjacent attacker to gain unauthorised access.

AI-generated illustration depicting vulnerability for the story: Schneider Electric Discloses Session-Management Flaw Across Broad OT Portfolio

A high-severity insufficient-entropy vulnerability in dozens of Schneider Electric protection relays, power automation systems, and related products could allow a network-adjacent attacker to gain unauthorised access.

Summary

  • CVE-2026-4827 (CVSS 8.3 HIGH) affects session-management in a large range of Schneider Electric Easergy, EcoStruxure, PowerLogic, and Saitel products used in energy, water, chemical, and critical manufacturing sectors.
  • The flaw stems from insufficient entropy in session tokens, allowing an attacker on the same network to exploit weak session protections and potentially obtain high levels of access to confidentiality and integrity.
  • Vendor fixes are available for most affected product lines; the Easergy MiCOM P30 and P40 series currently have no patch and rely on interim network-segmentation controls.
  • Affected products are deployed worldwide across critical infrastructure; organisations should prioritise patching and verify whether unpatched P30 and P40 devices exist on their OT networks.
  • CISA republished the Schneider Electric CPCERT advisory on 18 June 2026 to increase visibility; the original advisory was released 12 May 2026.

What Has Been Disclosed

Schneider Electric’s product cybersecurity team (CPCERT) has published an advisory covering a single, high-severity vulnerability — CVE-2026-4827 — that affects session management across a substantial portion of its operational technology portfolio. The advisory was subsequently republished by CISA on 18 June 2026 to broaden awareness. The affected products span protection relays, power automation gateways, user interfaces, and remote terminal units sold under the Easergy, EcoStruxure, PowerLogic, and Saitel brands.

The Technical Problem

The vulnerability is classified as CWE-331: Insufficient Entropy. In practical terms, session tokens generated by the affected products do not incorporate enough randomness, making them predictable under certain conditions. An attacker who already has access to the same network segment can exploit this weakness to hijack an active or recent session without valid credentials. The CVSS v3.1 base score is 8.3, reflecting network accessibility, no privilege requirement, no need for special configuration, and high impact to both confidentiality and integrity — though the availability impact is rated low.

Scope of Affected Products

The breadth of this advisory is notable. More than two dozen distinct product lines are listed, including multiple generations of Easergy MiCOM protection relays (P138, P139, P436 through P638, C264, C434, C5), the EcoStruxure Power Automation System Gateway and User Interface, EcoStruxure Power Operation versions 2022 and 2024, PowerLogic P5 and P7 protection relays, PowerLogic T300 and T500 RTUs, iPMFLS, and Saitel DP and DR devices. These products are used across critical infrastructure sectors including energy, water and wastewater, chemical, and critical manufacturing, and are deployed globally.

Patch Availability Varies

Schneider Electric has released fixed firmware or software versions for most of the affected product lines. Remediated versions include EcoStruxure Power Operation 2022 CU7 and 2024 CU3, EPAS Gateway 6.4.610.500.101, EPAS-UI 3.0.4, PowerLogic P5 V02.503.101, PowerLogic P7 V02.003.001, PowerLogic T300 2.9.5, PowerLogic T500 11.08.03, Easergy C5 1.1.18, and MiCOM C264 D7.34, among others. Several of these updates require a device reboot to take effect. For most products, the fix must be obtained by contacting Schneider Electric’s Customer Care Centre or a local Application Centre, rather than through a self-service download portal.

Where No Patch Yet Exists

The Easergy MiCOM P30 series models — specifically the P437, P532, P631, P634, P436, P438, and P638 — do not yet have a remediated firmware version. The same applies to the Easergy MiCOM P40 series where the Protocol Option bit is G, H, or L. Schneider Electric states it is establishing a remediation plan for both product families and will update the advisory when a fix is available. Operators of these devices must currently rely on interim controls.

Interim Controls for Unpatched Devices

For P30 and P40 devices awaiting a patch, Schneider Electric recommends two specific actions: ensure the devices operate within a physically or logically segmented network with access controlled by firewalls and intrusion detection systems; and use the CAE tool to reduce the minimum inactivity period, shortening session timeout durations to limit the window of exposure from idle sessions. These mitigations also apply to any organisation that cannot immediately apply available patches.

Why it matters

For CISOs responsible for operational technology environments, this advisory represents a meaningful exposure across a wide installed base of grid protection and power management equipment. A session-hijacking vulnerability in protection relays and power automation systems — where an adversary could gain high levels of access to device configuration and operational data — carries real consequences for grid stability and operational continuity. The absence of a patch for P30 and P40 series devices means some organisations must manage risk through network controls alone, which requires confidence that OT network segmentation is actually implemented and effective rather than assumed. Given the worldwide deployment footprint and the critical infrastructure sectors involved, asset owners should treat this as a priority inventory and patching exercise, not a routine update cycle.

What to do now

  • Conduct an immediate inventory of all Schneider Electric Easergy, EcoStruxure, PowerLogic, and Saitel devices in your environment and compare firmware versions against the affected version ranges listed in the advisory.
  • Apply available vendor firmware and software updates for affected products, obtaining update packages through Schneider Electric’s Customer Care Centre where direct download is not available. Plan for device reboots where required.
  • For EcoStruxure Power Operation, apply 2022 CU7 or 2024 CU3 as appropriate; these are available via the Schneider Electric community portal.
  • For unpatched P30 and P40 series relays, verify and enforce network segmentation — confirm these devices sit behind firewalls and IDS systems on isolated OT network segments, not reachable from business or external networks.
  • Use the CAE tool to reduce the minimum inactivity period on P30 and P40 devices, shortening session timeouts to reduce the exposure window from idle authenticated sessions.
  • Ensure no affected OT devices are accessible from the internet, and that remote access to these environments is enforced through a current, patched VPN solution.
  • Report any suspected malicious activity targeting these systems to CISA and follow established internal OT incident response procedures.

Sources