OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-97212

HIGH · CVSS 7.3 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the WebSocket backend, which improperly manages session identifiers, allowing multiple endpoints to connect using the same identifier. This flaw can lead to unauthorized access, enabling attackers to impersonate legitimate users, or potentially trigger a denial-of-service condition by flooding the backend with valid session requests. Organizations utilizing this WebSocket implementation should prioritize remediation to protect against these significant security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-97212
Severity
HIGH
CVSS
7.3
EPSS
0.25%

Original NVD Description

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.