Uncontrolled Resource Consumption Vulnerability in Schneider Electric's Web Admin Interface
CVE-2026-2405
5.3MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-2405?
A vulnerability exists in Schneider Electric's Web Admin Interface that leads to uncontrolled resource consumption. An attacker can exploit this flaw by sending excessive POST /helpabout requests, which could overwhelm the system and lead to the creation of numerous troubleshooting zip files. This excessive demand can ultimately result in a denial of service, disrupting operational efficiency and access to the interface.
Affected Version(s)
PowerChute™ Serial Shutdown Versions 1.4 and prior