mediumOther

Schneider Electric PowerChute Serial Shutdown Improper Authentication Attempt Restriction (CVE-2026-13348)

First seen Sep 20, 2026 · Updated Sep 20, 2026 · CVSS 5.3

ICSOTauthentication-bypassUPSschneider-electricCWE-307vulnerability-advisory

Schneider Electric disclosed CVE-2026-13348, a medium-severity vulnerability in PowerChute Serial Shutdown (versions 1.5 and prior) caused by improper restriction of excessive authentication attempts. An attacker could conduct unlimited authentication attempts against user accounts when redirect handling is disabled, potentially gaining unauthorized access. A vendor fix is available in version 1.6.

Technical Analysis

CVE-2026-13348 is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) with a CVSS v3.1 score of 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N), indicating network-exploitable, low-complexity, no-privilege-required access with limited confidentiality impact only. The flaw allows an attacker to perform brute-force or credential-stuffing style authentication attempts against PowerChute Serial Shutdown when redirect handling is disabled, potentially leading to unauthorized account access. Exploitation could allow attackers to disrupt UPS management functions, affecting graceful shutdown operations for desktops, servers, and workstations relying on this software for power management. There is no remote code execution or integrity/availability impact per the CVSS vector, limiting this to unauthorized access risk rather than full system compromise. Organizations running AI agent workloads on servers protected by affected PowerChute Serial Shutdown deployments could see unplanned or attacker-triggered shutdown disruptions if authentication is bypassed, impacting availability of agent infrastructure, though this is an indirect operational risk rather than a direct agent-framework compromise.

Affected Systems

Schneider Electric PowerChute Serial Shutdown version 1.5 and prior (Windows and Linux); fixed in version 1.6

Indicators of Compromise

  • No specific indicators of compromise provided; this is a vulnerability advisory rather than an active exploitation report

Remediation Steps

  1. 1

    Upgrade to PowerChute Serial Shutdown v1.6

    Download and install version 1.6 from Schneider Electric's official download portal for Windows or Linux. Verify successful installation via the version information in Control Panel or the About page within PCSS.

  2. 2

    Apply hardening guidance

    Follow the Security Handbook instructions provided by Schneider Electric for additional hardening of PowerChute deployments.

  3. 3

    Network segmentation

    Isolate control and safety system networks, including UPS management systems, from business networks and the public internet using firewalls.

  4. 4

    Restrict remote access

    Where remote access is required, use VPNs with up-to-date patching, and avoid exposing PowerChute management interfaces directly to the internet.

  5. 5

    Monitor authentication logs

    Review authentication logs for repeated failed login attempts that may indicate brute-force activity against PowerChute Serial Shutdown accounts.

CVE / Advisory IDs

CVE-2026-13348

Industries Most Exposed

Commercial FacilitiesCritical ManufacturingEnergyInformation Technology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.