CVE-2026-2405
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger d...
Affects 1 product across 2 vendors.
Software does not properly limit resource usage, allowing an attacker to exhaust CPU, memory, disk, or bandwidth.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A vulnerability exists in the system that could lead to excessive troubleshooting zip file creation and denial of service due to uncontrolled resource consumption when a Web Admin user floods the system with POST /helpabout requests.
BSID: BS-2026-GLOBAL-078769-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-2405?
What is the CVSS score for CVE-2026-2405?
Is CVE-2026-2405 actively exploited?
How do I remediate CVE-2026-2405?
What systems are affected by CVE-2026-2405?
| CVE ID | CVE-2026-2405 |
|---|---|
| BSID | BS-2026-GLOBAL-078769-M BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| Published | 2026-07-09 |
| Last Modified | 2026-07-09 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial‑of‑service conditions, truncate or alter logging information, reset user credentials, or expose sensitive information. The following versions of Schneider Electric PowerChute Serial Shutdown are affected: PowerChute Serial Shutdown <=1.4 CVSS Vendor Equipment Vulnerabilities v3 6.1 SuSE, Schneide
Source: NIST NVD / MITRE CVE Database
The attack vector involves a Web Admin user sending a large number of POST requests to the /helpabout endpoint, which triggers the creation of troubleshooting zip files. This can exhaust system resources, leading to a denial of service.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Schneider-Electric | Powerchute Serial Shutdown | — |
| Wolfram Schneider | — | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 5dd8ec225ebca62e5e8ecd936e8c087fb3362f2f27fc7326f50efb842a1b67119b5b3cbea022ddc8f16de4b099acc9a3a6c8f9f3846fdec77e957539ac314a67 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →