CVE-2026-2401
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger d...
Affects 1 product across 2 vendors.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A vulnerability exists in the Web Admin interface that could allow an attacker to insert sensitive information into log files, potentially exposing confidential data.
BSID: BS-2026-GLOBAL-078753-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-2401?
What is the CVSS score for CVE-2026-2401?
Is CVE-2026-2401 actively exploited?
How do I remediate CVE-2026-2401?
What systems are affected by CVE-2026-2401?
| CVE ID | CVE-2026-2401 |
|---|---|
| BSID | BS-2026-GLOBAL-078753-M BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
| Published | 2026-07-09 |
| Last Modified | 2026-07-09 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial‑of‑service conditions, truncate or alter logging information, reset user credentials, or expose sensitive information. The following versions of Schneider Electric PowerChute Serial Shutdown are affected: PowerChute Serial Shutdown <=1.4 CVSS Vendor Equipment Vulnerabilities v3 6.1 SuSE, Schneide
Source: NIST NVD / MITRE CVE Database
An attacker can exploit this vulnerability by providing a malicious file to a Web Admin user. When the file is executed, it can insert sensitive information into the system's log files, which may be accessible to unauthorized parties.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Schneider-Electric | Powerchute Serial Shutdown | — |
| Wolfram Schneider | — | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 78ff036b52c917c030ca515b880e72e5bc5cb53b17ebc7657c6fb74f87d0993adae4ae6fd07395768bb4852821f3b301b47314082979c738f373d94776b3c247 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →