CVE-2026-2403
CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsettings request payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2403?
CVE-2026-2403 is classified as a medium severity vulnerability due to improper validation of input, which can lead to data integrity issues.
How do I fix CVE-2026-2403?
To fix CVE-2026-2403, ensure that you update your Schneider Electric PowerChute Serial Shutdown software to version 1.5 or later.
What is the impact of CVE-2026-2403?
CVE-2026-2403 can lead to event and data log truncation, which affects the integrity of logged data.
Who is affected by CVE-2026-2403?
CVE-2026-2403 affects users of Schneider Electric PowerChute Serial Shutdown versions prior to 1.5.
Is CVE-2026-2403 actively exploited?
There is no information indicating that CVE-2026-2403 is actively being exploited in the wild.