CVE-2026-20781
Severity CVSS v4.0:
CRITICAL
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
27/02/2026
Last modified:
05/03/2026
Description
WebSocket endpoints lack proper authentication mechanisms, enabling <br />
attackers to perform unauthorized station impersonation and manipulate <br />
data sent to the backend. An unauthenticated attacker can connect to the<br />
OCPP WebSocket endpoint using a known or discovered charging station <br />
identifier, then issue or receive OCPP commands as a legitimate charger.<br />
Given that no authentication is required, this can lead to privilege <br />
escalation, unauthorized control of charging infrastructure, and <br />
corruption of charging network data reported to the backend.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.40
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cloudcharge:cloudcharge.se:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



