CVE-2026-44098
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
30/07/2026
Last modified:
30/07/2026
Description
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.
Impact
Base Score 4.0
8.80
Severity 4.0
HIGH
Base Score 3.x
8.60
Severity 3.x
HIGH



