HomeIntelligenceBrief
VULNERABILITY BRIEF 🟡 Medium Vulnerability

Improper Authentication Controls in Schneider Electric PowerChute Serial Shutdown (CVE‑2026‑13348) Pose Risk to Critical Infrastructure

Schneider Electric’s PowerChute Serial Shutdown UPS‑management software (versions ≤ 1.5 and 1.6) contains a flaw that fails to limit repeated login attempts, potentially allowing unauthorized access. The issue highlights the need for enforceable account‑lockout controls and auditable logging to satisfy trust‑and‑control assurance requirements.

Verisq™ Intelligence · 📅 September 17, 2026 · 📰 cisa.gov
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Improper Authentication Controls in Schneider Electric PowerChute Serial Shutdown (CVE‑2026‑13348)

What It Is – Schneider Electric’s PowerChute Serial Shutdown UPS‑management software contains an authentication‑logic flaw (CVE‑2026‑13348) that fails to limit excessive login attempts when redirect handling is disabled.

Exploitability – The vulnerability is publicly disclosed with a CVSS v3.1 base score of 5.3 (Moderate). No public exploit has been observed, but the flaw is trivially exploitable by brute‑force attempts.

Affected Products – Schneider Electric PowerChute Serial Shutdown ≤ 1.5 and 1.6.

Why It Matters for Trust & Control Assurance

  • Control Objective – Account Lockout & Brute‑Force Mitigation – The issue tests the control that limits repeated authentication attempts, a core element of identity‑and‑access‑management assurance.
  • Evidence‑Ready Monitoring – Continuous logging of failed logins and lockout events provides defensible audit evidence required by buyers across NIST CSF 2.0 and other frameworks.
  • Supply‑Chain Trust – PowerChute is deployed in commercial facilities, critical manufacturing, energy and IT environments; a breach would erode the trust posture of any organization that relies on Schneider’s UPS management stack.

Recommended Actions

  1. Apply Schneider Electric’s remediation patch for versions ≤ 1.5 and 1.6 immediately.
  2. Enforce account lockout policies (e.g., max 5 failed attempts, exponential back‑off) and verify they are logged.
  3. Integrate authentication logs into a SIEM or continuous‑monitoring platform to produce audit‑ready evidence of control effectiveness.
  4. Conduct a post‑patch validation test to confirm the lockout mechanism functions as intended.

Source: CISA Advisory – ICSA‑26‑260‑07

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-07

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →