CVE-2026-29796 is a critical vulnerability impacting OCPP WebSocket endpoints, stemming from a lack of proper authentication mechanisms. This flaw allows unauthenticated attackers to impersonate legitimate charging stations by connecting with known identifiers, enabling them to issue or receive OCPP commands. Rated 9.4 CRITICAL, the vulnerability permits remote attackers to achieve privilege escalation, gain unauthorized control of charging infrastructure, and corrupt network data. While there is no public exploit code or evidence of active exploitation, the issue has generated some community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:igl:eparking.fi:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.