CVE-2026-2399 is a path traversal vulnerability (CWE-22) affecting Web Admin functionality in unspecified products that allows critical system files to be overwritten with arbitrary text data through manipulation of POST requests to the /REST/upssleep endpoint. The vulnerability requires an authenticated Web Admin user to exploit, making it a privilege abuse scenario rather than an unauthenticated attack vector. The vulnerability carries a CVSS v3.1 score of 6.1 (Medium), with an adjacent network attack vector and low complexity. While confidentiality is not impacted, the vulnerability poses significant integrity and availability risks through unauthorized file overwriting of critical system components. The FAUCET Risk Score of 34.0 out of 100 indicates moderate concern from a holistic risk perspective. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. The extremely low EPSS score of 0.00024 suggests minimal real-world exploitation probability, indicating this is likely a lower-priority remediation item relative to higher-severity threats, though patching should still be scheduled as part of routine maintenance cycles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5CPE matchmatch criteria | cpe:2.3:a:schneider-electric:powerchute_serial_shutdown:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.