news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-56451

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
10.0 Critical
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Risk score
80.0
Published
2026-07-14
Status
Published

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.

Weaknesses

CWE-347

Coverage 1

vulnerability

Siemens Opcenter X

Siemens Opcenter X versions prior to V2604 contain a critical authentication bypass vulnerability, allowing an unauthenticated attacker to gain full unauthorized access to the application. Siemens has released a new vers…

CISA Advisories · Jul 21, 2026 Critical

Advisories and references