CVE-2026-2399: Path Traversal
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep request payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2399?
CVE-2026-2399 has a critical severity rating due to its potential to overwrite critical files.
How do I fix CVE-2026-2399?
To fix CVE-2026-2399, ensure you upgrade to a patched version of Schneider Electric's PowerChute Serial Shutdown above version 1.5.
Who is affected by CVE-2026-2399?
CVE-2026-2399 affects users of Schneider Electric's PowerChute Serial Shutdown software versions up to 1.5.
What type of vulnerability is CVE-2026-2399?
CVE-2026-2399 is a Path Traversal vulnerability that improperly limits pathname access.
What can happen if CVE-2026-2399 is exploited?
If exploited, CVE-2026-2399 can lead to critical files being overwritten with unintended text data.