CVE-2026-2401

MEDIUM

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger d...

Affects 1 product across 2 vendors.

BCS3.56
CVSS 3.15.0
CVSS v42.4
EPSS0.1%
Percentile1th
PatchUnknown
CVSS Vector — Plain English Requires local access, low complexity, low privileges required, requires user interaction, impact contained to the vulnerable component, full confidentiality impact, no integrity impact, no availability impact.
CWE Weakness Definitions
CWE-532: CWE-532
Related Attack Patterns (CAPEC)
CAPEC-215 Fuzzing for application mapping
via CWE-532

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability exists in the Web Admin interface that could allow an attacker to insert sensitive information into log files, potentially exposing confidential data.

BSID: BS-2026-GLOBAL-078753-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-2401?
A vulnerability exists in the Web Admin interface that could allow an attacker to insert sensitive information into log files, potentially exposing confidential data.
What is the CVSS score for CVE-2026-2401?
CVE-2026-2401 has CVSS 5.0 (Medium). Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N. EPSS: 0.1%.
Is CVE-2026-2401 actively exploited?
No confirmed active exploitation of CVE-2026-2401 as of 2026-07-10.
How do I remediate CVE-2026-2401?
Priority: MEDIUM. Advisory: https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-104-01.pdf PSIRT: [email protected]
What systems are affected by CVE-2026-2401?
CVE-2026-2401 affects: Schneider-Electric, Wolfram Schneider.
Vulnerability Details
CVE IDCVE-2026-2401
BSIDBS-2026-GLOBAL-078753-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Published2026-07-09
Last Modified2026-07-09
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial‑of‑service conditions, truncate or alter logging information, reset user credentials, or expose sensitive information. The following versions of Schneider Electric PowerChute Serial Shutdown are affected: PowerChute Serial Shutdown <=1.4 CVSS Vendor Equipment Vulnerabilities v3 6.1 SuSE, Schneide

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by providing a malicious file to a Web Admin user. When the file is executed, it can insert sensitive information into the system's log files, which may be accessible to unauthorized parties.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Schneider-Electric Powerchute Serial Shutdown
Wolfram Schneider &mdash;
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 16 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash78ff036b52c917c030ca515b880e72e5bc5cb53b17ebc7657c6fb74f87d0993adae4ae6fd07395768bb4852821f3b301b47314082979c738f373d94776b3c247
Related CVEs affecting Schneider-Electric
CVE-2011-4861 10.0 The modbus_125_handler function in the Schneider Electric Quantum Ethernet Mo... CVE-2013-0657 10.0 Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA... CVE-2020-11897 10.0 The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multipl... CVE-2020-11896 10.0 The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related ... CVE-2013-3075 10.0 Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3...
View all Schneider-Electric CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →