CVE-2026-2402
Last modified
CVE-2026-2402 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on a sequence of requests to multiple endpoints.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on a sequence of requests to multiple endpoints.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Powerchute Serial Shutdown | < 1.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-2402?
How severe is CVE-2026-2402?
How do I fix CVE-2026-2402?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-24013Authentication Bypass by Spoofing vulnerability in Apache Io…9.1
- CVE-2026-24014Apache IoTDB DataNode’s internal RPC interface for creating …9.8
- CVE-2026-24015A vulnerability in Apache IoTDB. This issue affects Apache …9.8
- CVE-2026-24016The installer of ServerView Agents for Windows provided by F…8.4
- CVE-2026-24017An Improper Control of Interaction Frequency vulnerability […8.1
- CVE-2026-24018A UNIX symbolic link (Symlink) following vulnerability in Fo…7.8
- CVE-2026-24020Rejected reason: Not used
- CVE-2026-24021Rejected reason: Not used
- CVE-2026-24022Rejected reason: Not used
- CVE-2026-24023Rejected reason: Not used
- CVE-2026-24024Rejected reason: Not used
- CVE-2026-24025Rejected reason: Not used
Are you affected by CVE-2026-2402?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
