CVE-2026-2399Disclosure(schneider-electric / powerchute_serial_shutdown)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep request payload.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • powerchute_serial_shutdown

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
powerchute_serial_shutdown

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-19: 2Mentions · 2026-07-10: 1Technical Details · 2026-04-19: 204-1907-10
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-192
Disclosure2
2026-07-101
General1
Full discourse3 posts
  • BREACHSPIDER@breachspider
    General

    [CVE Analysis] CVE-2026-2399: Schneider Electric PowerChute Serial Shutdown Flaws Threaten Graceful Shutdown Integrity https://breachspider.com/intel/2026-07-10-cve-2026-2399-schneider-electric-powerchute-serial-shutdown #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The provided text offers minimal information, mentioning only the existence of serial shutdown flaws in Schneider Electric PowerChute without detailed technical specifics, patches, or exploitation evidence.

    0000068
    2.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2399 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data wh… https://www.cve.org/CVERecord?id=CVE-2026-2399 ----- Traducción: CVE-2026-2399 CWE… http://infoflow.cloud`

    Post summary

    The tweet announces the existence of CVE-2026-2399, describing it as a path‑traversal flaw that could overwrite critical files, but provides no further details on exploitation, patches, or PoC.

    0000037
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2399 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data wh… https://www.cve.org/CVERecord?id=CVE-2026-2399

    Post summary

    The feed announces CVE-2026-2399 as a path‑traversal flaw capable of overwriting critical files but provides no PoC, exploitation evidence, or mitigation advice.

    00000176
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appschneider-electricpowerchute_serial_shutdown---

Explore more