Junglewise Threat Intelligence

CVE-2026-13348: Schneider Electric PowerChute Serial Shutdown improper authentication restriction

CVE-2026-13348 · Severity: high · CVSS 5.3 · Published 2026-09-17

Executive brief

PowerChute Serial Shutdown is a UPS management application that controls graceful system shutdowns and energy management across desktops, servers, and workstations in critical infrastructure environments. A flaw in its authentication logic allows attackers to perform unlimited login attempts without rate limiting, potentially leading to unauthorized account access and exposure of system data or operational disruption in energy, manufacturing, and other critical sectors worldwide.

Technical details

The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) and exists in PowerChute Serial Shutdown versions 1.5 and earlier. The flaw allows an attacker to conduct arbitrary brute-force authentication attempts against user accounts when redirect handling is disabled. The attack requires network access to the UPS management interface (CVSS attack vector: network) but no authentication or user interaction. An attacker can leverage this to bypass authentication and gain unauthorized access to the system, potentially disrupting operations or accessing sensitive system data. Schneider Electric released version 1.6 as a fix; the service automatically restarts upon installation with version confirmation available in Control Panel or the application's About page.

Affected products

  • Schneider Electric PowerChute Serial Shutdown <=1.5, 1.6

Timeline

  • 2026-09-17: disclosed: CISA advisory ICSA-26-260-07 published
  • 2026-09-17: patched: Version 1.6 released with fix

References