CVE-2026-56451
Eine Schwachstelle wurde in Opcenter X (alle Versionen < V2604) identifiziert.
criticalEPSS 0.5%
Description
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.
Metrics
Show all metrics
Severity
critical
85.47
no public PoC known
10.0
10.0
Published
2026-07-14 10:16 UTC
CWE-347
Weakness classes (CWE)
CWE-347Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
cwe.mitre.org →