CVE-2026-2402

CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on a sequence of requests to multiple endpoints.
Configurations

Configuration 1 (hide)

cpe:2.3:a:schneider-electric:powerchute_serial_shutdown:*:*:*:*:*:*:*:*

History

22 Apr 2026, 14:11

Type Values Removed Values Added
References () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf - () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf - Vendor Advisory
CPE cpe:2.3:a:schneider-electric:powerchute_serial_shutdown:*:*:*:*:*:*:*:*
First Time Schneider-electric
Schneider-electric powerchute Serial Shutdown
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

14 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-14 16:16

Updated : 2026-04-22 14:11


NVD link : CVE-2026-2402

Mitre link : CVE-2026-2402

CVE.ORG link : CVE-2026-2402


JSON object : View

Products Affected

schneider-electric

  • powerchute_serial_shutdown
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts