Skip to content
Threat Feed
medium advisory

Authentication Bypass Vulnerability in Schneider Electric PowerChute Serial Shutdown

Schneider Electric PowerChute Serial Shutdown version 1.5 and prior contains an improper restriction of excessive authentication attempts vulnerability (CVE-2026-13348) that may allow unauthorized account access via brute-force.

CVE search metadata

CVE search record: CVE-2026-13348. EPSS: 0.31%. KEV: no. Product: PowerChute Serial Shutdown (<= 1.5). Brief: Authentication Bypass Vulnerability in Schneider Electric PowerChute Serial Shutdown. Brief link: https://feed.craftedsignal.io/briefs/2026-09-schneider-powerchute-auth/

Schneider Electric has identified a vulnerability in its PowerChute Serial Shutdown software, which is used for UPS management and system energy control. The vulnerability, tracked as CVE-2026-13348, is an instance of CWE-307: Improper Restriction of Excessive Authentication Attempts. This flaw exists in versions 1.5 and prior of the application.

The vulnerability allows an attacker to perform an arbitrary number of authentication attempts against the software when redirect handling is disabled. Because the application fails to adequately throttle or block repeated login requests, it is susceptible to brute-force attacks. Successful exploitation could lead to unauthorized access to a user account, potentially allowing an adversary to manipulate power management settings or disrupt critical system operations. Given that this software often operates in industrial, energy, and IT environments, unauthorized access poses a risk to operational stability.

Impact

The vulnerability affects users of PowerChute Serial Shutdown across multiple sectors including energy, manufacturing, and commercial facilities worldwide. If exploited, an attacker could gain administrative or user-level access to the application, resulting in the potential disruption of system shutdowns, energy management services, and unauthorized access to system configuration data.

Recommendation

Prioritize the remediation of CVE-2026-13348 by upgrading all instances of PowerChute Serial Shutdown to version 1.6 or later.

  • Upgrade PowerChute Serial Shutdown on all Windows hosts to v1.6 via the official Schneider Electric download portal.
  • Upgrade PowerChute Serial Shutdown on all Linux hosts to v1.6 via the official Schneider Electric download portal.
  • Ensure that PowerChute management interfaces are isolated from public-facing networks and restricted to trusted administrative segments, as recommended in the Schneider Electric Security Handbook.
  • Monitor authentication logs for the PowerChute application for patterns indicative of high-frequency login failures or brute-force activity.

Immediate actions

Upgrade PowerChute Serial Shutdown to version 1.6

IT Operations 72h

Mitigations

Isolate PowerChute management interfaces behind firewalls

immediate Network Security

CVE-2026-13348