SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-56451

CRITICAL · CVSS 10 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Opcenter X versions prior to V2604 are vulnerable due to improper validation of the algorithm in the JSON Web Token (JWT) header, allowing unauthenticated remote attackers to forge JWTs. This critical vulnerability enables attackers to bypass authentication, impersonate any user, including administrators, and gain full unauthorized access to the application. Organizations using affected versions should prioritize immediate patching to mitigate potential exploitation.

CVE
CVE-2026-56451
Severity
CRITICAL
CVSS
10
EPSS
0.30%

Original NVD Description

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.