Improper Authentication Controls in Schneider Electric PowerChute Serial Shutdown (CVE‑2026‑13348)
What It Is – Schneider Electric’s PowerChute Serial Shutdown UPS‑management software contains an authentication‑logic flaw (CVE‑2026‑13348) that fails to limit excessive login attempts when redirect handling is disabled.
Exploitability – The vulnerability is publicly disclosed with a CVSS v3.1 base score of 5.3 (Moderate). No public exploit has been observed, but the flaw is trivially exploitable by brute‑force attempts.
Affected Products – Schneider Electric PowerChute Serial Shutdown ≤ 1.5 and 1.6.
Why It Matters for Trust & Control Assurance
- Control Objective – Account Lockout & Brute‑Force Mitigation – The issue tests the control that limits repeated authentication attempts, a core element of identity‑and‑access‑management assurance.
- Evidence‑Ready Monitoring – Continuous logging of failed logins and lockout events provides defensible audit evidence required by buyers across NIST CSF 2.0 and other frameworks.
- Supply‑Chain Trust – PowerChute is deployed in commercial facilities, critical manufacturing, energy and IT environments; a breach would erode the trust posture of any organization that relies on Schneider’s UPS management stack.
Recommended Actions
- Apply Schneider Electric’s remediation patch for versions ≤ 1.5 and 1.6 immediately.
- Enforce account lockout policies (e.g., max 5 failed attempts, exponential back‑off) and verify they are logged.
- Integrate authentication logs into a SIEM or continuous‑monitoring platform to produce audit‑ready evidence of control effectiveness.
- Conduct a post‑patch validation test to confirm the lockout mechanism functions as intended.
Source: CISA Advisory – ICSA‑26‑260‑07