CVE-2026-2401
MEDIUMSchneider Electric PowerChute Serial Shutdown <=1.4 - Info Disclosure
Title source: llmDescription
CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker.
Scores
CVSS v3
5.0
EPSS
0.0001
EPSS Percentile
2.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-532
Status
published
Products (2)
Schneider Electric/PowerChute™ Serial Shutdown
Versions 1.4 and prior
schneider-electric/powerchute_serial_shutdown
< 1.5
Published
Apr 14, 2026
Tracked Since
Apr 14, 2026