SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-44102

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

An unauthenticated remote attacker can exploit a vulnerability in the OCPP backend to initiate a firmware update download with an invalid firmware file, leading to temporary exposure of the file before it is deleted. This flaw poses a risk of unauthorized access to potentially sensitive firmware data, making it critical for organizations utilizing OCPP systems to prioritize remediation efforts. Users of affected products should assess their exposure and implement necessary security measures to mitigate this risk.

CVE
CVE-2026-44102
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%

Original NVD Description

An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.