CVE-2026-4827
View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChuteâ„¢ Serial Shutdown product. The [PowerChute Serial Shutdown](https://www.se.com/ww/en/product-range/137943580-powerc...
Affects 0 products across 2 vendors.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A CWE-331 Insufficient Entropy vulnerability exists, which could allow an attacker to exploit weaknesses in session-management protections, leading to unauthorized access.
BSID: BS-2026-GLOBAL-153940-I • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-4827?
Is CVE-2026-4827 actively exploited?
How do I remediate CVE-2026-4827?
What systems are affected by CVE-2026-4827?
| CVE ID | CVE-2026-4827 |
|---|---|
| BSID | BS-2026-GLOBAL-153940-I BreachSpider Global ID |
| Published | 2026-06-18 |
| Last Modified | 2026-06-18 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChuteâ„¢ Serial Shutdown product. The [PowerChute Serial Shutdown](https://www.se.com/ww/en/product-range/137943580-powerchute-serial-shutdown/#products) product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktop, servers and workstations. Failure to apply the remediation provided below may risk improper input validation which could result in disruption of operati
Source: NIST NVD / MITRE CVE Database
An attacker on the network could exploit this vulnerability by predicting or brute-forcing session tokens due to insufficient entropy, thereby gaining unauthorized access to user sessions.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Schneider-Electric | — | — |
| Wolfram Schneider | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →