CVE-2026-2399
CVE-2026-2399 is a medium-severity vulnerability in Schneider-electric Powerchute Serial Shutdown with a CVSS 3.x base score of 6.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 3.x base score 6.1)
- CVSS v4: 6.9
- EPSS exploit prediction: 0% (11th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-22282
- Weakness: CWE-22
- Affected product: Schneider-electric Powerchute Serial Shutdown
- Published:
- Last modified:
Description
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep request payload.
Frequently asked questions
- What is CVE-2026-2399?
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep request payload.
- How severe is CVE-2026-2399?
- CVE-2026-2399 has a CVSS 3.x base score of 6.1, rated medium severity. It is exploitable over an adjacent network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability high.
- Is CVE-2026-2399 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (11th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-2399?
- CVE-2026-2399 affects Schneider-electric Powerchute Serial Shutdown. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-2399?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-2399 have an EU (EUVD) identifier?
- Yes. CVE-2026-2399 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-22282.
- When was CVE-2026-2399 published?
- CVE-2026-2399 was published on 2026-04-14 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:schneider-electric:powerchute_serial_shutdown:*:*:*:*:*:*:*:*
More vulnerabilities in Schneider-electric Powerchute Serial Shutdown
- CVE-2026-2405 — Medium (CVSS 6.5): CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file…
- CVE-2026-2404 — Medium (CVSS 5.3): CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when…
- CVE-2026-2402 — Medium (CVSS 5.3): CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to…
- CVE-2026-2401 — Medium (CVSS 5.0): CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential…
- CVE-2026-2403 — Medium (CVSS 4.3): CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log…
- CVE-2026-2400 — Medium (CVSS 4.3): CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application…
All CVEs affecting Schneider-electric Powerchute Serial Shutdown →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.