CVE-2026-2403
MEDIUMSchneider Electric PowerChute Serial Shutdown <=1.4 - Log Truncation
Title source: llmDescription
CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsettings request payload.
Scores
CVSS v3
4.3
EPSS
0.0005
EPSS Percentile
15.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1284
Status
published
Products (2)
Schneider Electric/PowerChute™ Serial Shutdown
Versions 1.4 and prior
schneider-electric/powerchute_serial_shutdown
< 1.5
Published
Apr 14, 2026
Tracked Since
Apr 14, 2026