SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-44098

HIGH · CVSS 8.6 EPSS 1.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary OS commands on the affected OCPP backend, potentially disrupting charging operations. Organizations utilizing this backend should prioritize remediation efforts, as the flaw allows for significant unauthorized control and could lead to service interruptions. Immediate action is recommended for those managing charging infrastructure to mitigate the risk of exploitation.

CVE
CVE-2026-44098
Severity
HIGH
CVSS
8.6
EPSS
1.37%

Original NVD Description

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.