SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-44383

HIGH · CVSS 7.5 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Multiple connections to the backend using the same charging station ID are permitted, enabling attackers to deploy numerous malicious OCPP clients that can overwhelm the backend system. This vulnerability poses a significant risk to the integrity and availability of services relying on this architecture. Organizations utilizing affected charging station systems should prioritize addressing this issue to mitigate potential disruptions and security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44383
Severity
HIGH
CVSS
7.5
EPSS
0.45%

Original NVD Description

Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.