PT-2026-58004 · Siemens · Opcenter X

CVE-2026-56451

·

Published

2026-07-14

·

Updated

2026-07-20

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Opcenter X versions prior to V2604
Description An issue exists where the application does not properly validate the algorithm specified in the JSON Web Token (JWT) header during token verification. This flaw, known as JWT algorithm confusion, allows an unauthenticated remote attacker to forge arbitrary tokens by manipulating the alg value in the header. By presenting these forged tokens to endpoints that trust JWT-based authentication, an attacker can bypass authentication mechanisms and impersonate any user, including administrative accounts, potentially gaining full unauthorized access to the application and its data.
Recommendations Upgrade to version V2604.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09949
CVE-2026-56451

Affected Products

Opcenter X