CVE-2026-4827

N/A

View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChuteâ„¢ Serial Shutdown product. The [PowerChute Serial Shutdown](https://www.se.com/ww/en/product-range/137943580-powerc...

Affects 0 products across 2 vendors.

BCS3.91
CVSS v48.7
EPSS0.3%
Percentile23th
PatchUnknown
CWE Weakness Definitions
CWE-331: CWE-331
Related Attack Patterns (CAPEC)
CAPEC-59 Session Credential Falsification through Prediction
via CWE-331

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A CWE-331 Insufficient Entropy vulnerability exists, which could allow an attacker to exploit weaknesses in session-management protections, leading to unauthorized access.

BSID: BS-2026-GLOBAL-153940-I • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-4827?
A CWE-331 Insufficient Entropy vulnerability exists, which could allow an attacker to exploit weaknesses in session-management protections, leading to unauthorized access.
Is CVE-2026-4827 actively exploited?
No confirmed active exploitation of CVE-2026-4827 as of 2026-06-22.
How do I remediate CVE-2026-4827?
Priority: HIGH.
What systems are affected by CVE-2026-4827?
CVE-2026-4827 affects: Schneider-Electric, Wolfram Schneider.
Vulnerability Details
CVE IDCVE-2026-4827
BSIDBS-2026-GLOBAL-153940-I BreachSpider Global ID
Published2026-06-18
Last Modified2026-06-18
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChuteâ„¢ Serial Shutdown product. The [PowerChute Serial Shutdown](https://www.se.com/ww/en/product-range/137943580-powerchute-serial-shutdown/#products) product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktop, servers and workstations. Failure to apply the remediation provided below may risk improper input validation which could result in disruption of operati

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker on the network could exploit this vulnerability by predicting or brute-forcing session tokens due to insufficient entropy, thereby gaining unauthorized access to user sessions.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Schneider-Electric —
Wolfram Schneider —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 37 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
Related CVEs affecting Schneider-Electric
CVE-2011-4861 10.0 The modbus_125_handler function in the Schneider Electric Quantum Ethernet Mo... CVE-2013-0657 10.0 Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA... CVE-2020-11897 10.0 The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multipl... CVE-2020-11896 10.0 The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related ... CVE-2013-3075 10.0 Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3...
View all Schneider-Electric CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →