CVE-2026-2402
published 2026-04-14CVE-2026-2402: CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by…
PriorityP336medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.27%
19.3th percentile
CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on a sequence of requests to multiple endpoints.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | powerchute_serial_shutdown | < 1.5 | 1.5 |
| schneider_electric | powerchute_serial_shutdown | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Schneider Electric PowerChute Serial Shutdown excessive authentication (SEVD-2026-104-01 / Nessus ID 306551)
vuldb·2026-04-16·CVSS 6.9
CVE-2026-2402 [MEDIUM] Schneider Electric PowerChute Serial Shutdown excessive authentication (SEVD-2026-104-01 / Nessus ID 306551)
A vulnerability was found in Schneider Electric PowerChute Serial Shutdown. It has been classified as problematic. Affected by this issue is some unknown functionality. Performing a manipulation results in improper restriction of excessive authentication attempts.
This vulnerability is cataloged as CVE-2026-2402. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to install a patch to address this issue.
GHSA
GHSA-gwjq-j584-rm32: CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account
ghsa_unreviewed·2026-04-14
CVE-2026-2402 [MEDIUM] CWE-307 GHSA-gwjq-j584-rm32: CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account
CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on a sequence of requests to multiple endpoints.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-14
Published