OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-95102

CRITICAL · CVSS 9.4 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

WebSocket endpoints are vulnerable due to inadequate authentication, allowing attackers to impersonate charging stations and gain unauthorized access to sensitive data or execute unauthorized actions. This critical flaw can lead to privilege escalation, jeopardizing the overall security of the system. Organizations utilizing WebSocket technology in their infrastructure should prioritize addressing this vulnerability to mitigate potential risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-95102
Severity
CRITICAL
CVSS
9.4
EPSS
0.34%

Original NVD Description

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.