Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-14354

CVE-2026-14354: Authentication Bypass Vulnerability

CVE-2026-14354 is an authentication bypass flaw caused by insufficiently protected credentials that allows local privileged attackers to modify credentials and compromise managed devices. This article covers technical details, impact, and mitigation.

Published:

CVE-2026-14354 Overview

CVE-2026-14354 is an Insufficiently Protected Credentials vulnerability [CWE-522] disclosed in a Schneider Electric product. The flaw allows a local privileged attacker to exploit weaknesses in how the application stores and handles credentials. Successful exploitation can lead to authentication bypass and unauthorized credential modification. The vendor advisory documents that this behavior may result in compromise of managed devices connected to the affected application.

Critical Impact

A local attacker with elevated privileges can bypass authentication and modify stored credentials, extending compromise from the host to any device managed through the application.

Affected Products

  • Schneider Electric product referenced in advisory SEVD-2026-195-02 (see vendor notice for affected versions)

Discovery Timeline

  • 2026-07-29 - CVE-2026-14354 published to NVD
  • 2026-07-30 - Last updated in NVD database

Technical Details for CVE-2026-14354

Vulnerability Analysis

The vulnerability originates in the credential storage and handling routines of the affected application. Credentials are held in a form that does not adequately resist local inspection or tampering by a privileged user. An attacker who already holds high privileges on the host can read, replace, or otherwise manipulate these credential artifacts. Because the application uses the same credentials to authenticate to managed devices, tampering with the store directly undermines downstream authentication.

The attack vector is Local, and the vulnerability requires high privileges and high attack complexity. However, the impact extends beyond the compromised host: confidentiality, integrity, and availability of both the vulnerable component and connected systems are affected. The EPSS score is 0.117%, reflecting a low observed likelihood of near-term exploitation as of publication.

Root Cause

The root cause is insufficient protection of stored credentials, classified as [CWE-522]. The application relies on protections that a locally privileged actor can defeat, such as reversible encoding, weak key derivation, or storage locations accessible with administrative rights. This design choice allows an attacker to bypass the intended authentication workflow entirely by substituting or extracting credentials directly.

Attack Vector

An attacker must first obtain local, high-privileged access to the system hosting the affected application. From that position, the attacker interacts with the credential store to read or modify entries. The application then presents the manipulated credentials to managed devices, enabling authentication bypass or lateral impact against those devices. No user interaction is required. Refer to the Schneider Electric Security Notice SEVD-2026-195-02 for product-specific technical detail.

Detection Methods for CVE-2026-14354

Indicators of Compromise

  • Unexpected read or write access to the application's credential store files or registry keys by non-application processes.
  • Modifications to managed-device credentials that do not correlate with administrative change tickets.
  • Successful authentications to managed devices originating from the application host outside normal operator hours.

Detection Strategies

  • Baseline file integrity monitoring on the credential store paths documented in SEVD-2026-195-02, and alert on any modification.
  • Correlate local privilege elevation events (token manipulation, service impersonation) with subsequent access to the application's install directory.
  • Track outbound authentication attempts from the application host to managed devices and flag credential resets or failed-then-succeeded sequences.

Monitoring Recommendations

  • Enable process-level auditing on the account under which the vulnerable application runs.
  • Forward Windows Security, application, and device authentication logs to a centralized SIEM for correlation.
  • Review privileged account usage on the application host on a recurring schedule and confirm each session against change management records.

How to Mitigate CVE-2026-14354

Immediate Actions Required

  • Restrict local administrative access on hosts running the affected Schneider Electric application to a minimal, audited set of accounts.
  • Apply the fixed version identified in Schneider Electric advisory SEVD-2026-195-02 as soon as it is validated in your environment.
  • Rotate credentials used by the application to authenticate to managed devices after patching.

Patch Information

Schneider Electric publishes patched versions and remediation steps in security notice SEVD-2026-195-02. Consult the notice for exact fixed builds, upgrade instructions, and any product-specific configuration hardening required after the update.

Workarounds

  • Segment the application host on a management-only network and block interactive logons from general-purpose workstations.
  • Enforce multi-factor authentication for any account that can log on locally to the application host.
  • Enable OS-level credential protection features such as Windows Credential Guard where the platform supports them.
  • Monitor the application's credential store paths with file integrity monitoring until the patch is deployed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.