SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-22100

HIGH · CVSS 8.6 EPSS 0.81%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability in the OCPP DataTransfer message `ReserveLogin` allows for command injection, enabling attackers to execute arbitrary OS commands with root privileges by manipulating the data value. This poses a significant risk to any systems utilizing this message, potentially leading to unauthorized access and control. Organizations using OCPP implementations should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-22100
Severity
HIGH
CVSS
8.6
EPSS
0.81%

Original NVD Description

The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitrary OS commands can be executed as root.