CVE-2026-26051 describes a critical vulnerability in WebSocket endpoints, where a lack of proper authentication allows unauthenticated attackers to impersonate charging stations and manipulate data. This affects charging infrastructure utilizing the OCPP WebSocket protocol. With a CVSS score of 9.4 (Critical), the vulnerability is easily exploitable over the network with low complexity, potentially leading to privilege escalation, unauthorized control of charging stations, and data corruption. There is currently no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed on the CISA KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:mvm:mobiliti_e-mobi.hu:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.