CVE-2026-27772Disclosure(ev.energy / ev.energy)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ev.energy

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-02-27); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
ev.energy

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-27: 4Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Technical Details · 2026-02-27: 4Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 102-2703-0303-04
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-274
Disclosure4
2026-03-031
General1
2026-03-041
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27772 (CVSS:9.4, CRITICAL) is Analyzed. WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona..https://nvd.nist.gov/vuln/detail/CVE-2026-27772 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post highlights CVE-2026-27772 as a critical WebSocket authentication flaw that permits unauthorized station impersonation, but it does not provide a PoC, exploit, or patch information.

    0000020
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27772 (CVSS:9.4, CRITICAL) is Analyzed. WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona..https://nvd.nist.gov/vuln/detail/CVE-2026-27772 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE‑2026‑27772, noting its critical severity and lack of authentication on WebSocket endpoints that could allow impersonation, but does not mention PoC, exploit, patch, or active exploitation.

    0000036
    173 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27772 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.… https://www.cve.org/CVERecord?id=CVE-2026-27772 ----- Traducción: CVE-2026-27772 Los… http://infoflow.cloud`

    Post summary

    A new CVE (CVE-2026-27772) is announced, noting that WebSocket endpoints lack authentication, allowing impersonation and data tampering; no PoC, exploit, patch, or active exploitation details are provided.

    0000025
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27772 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.… https://www.cve.org/CVERecord?id=CVE-2026-27772

    Post summary

    The post discloses that CVE‑2026‑27772 allows attackers to impersonate stations and manipulate backend data via WebSocket endpoints lacking proper authentication.

    00000158
    56.6K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27772** pertains to a critical security flaw in systems utilizing WebSocket endpoints for the Open Charge Point Protocol (OCPP). Specifically, the vulnerability arises because these WebSocket endpoints lack proper authentication mechanisms, allowing unauthenticated attackers to connect and impersonate legitimate charging stations. This flaw enables malicious actors to send or receive OCPP commands, manipulate charging data, and potentially control or disrupt charging infrastructure. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation #Apple https://cvetodo.com/cve/CVE-2026-27772

    Post summary

    CVE‑2026‑27772 is a critical flaw in OCPP WebSocket endpoints that lack authentication, enabling unauthenticated attackers to impersonate charging stations, send commands, and potentially disrupt charging infrastructure.

    0000039
    20 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-27772: CRITICAL] Unauthenticated access to WebSocket endpoints can lead to unauthorized control of charging systems, manipulation of data, and privilege escalation. #cybersecurity#cve,CVE-2026-27772,#cybersecurity https://cvefind.com/CVE-2026-27772

    Post summary

    CVE-2026-27772 is a critical vulnerability that permits unauthenticated access to WebSocket endpoints in charging systems, enabling unauthorized control, data manipulation, and privilege escalation.

    0000047
    585 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appev.energyev.energy---

Explore more