CVE-2026-29796Disclosure(igl / eparking.fi)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • eparking.fi

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-20); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
eparking.fi

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-20: 3Mentions · 2026-03-21: 2PoC Mentioned / Linked · 2026-03-20: 1Technical Details · 2026-03-20: 3Technical Details · 2026-03-21: 203-2003-21
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-203
Disclosure3
2026-03-212
Disclosure1General1
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-29796 WebSocket Authentication Bypass in OCPP Charging Station Management System https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29796

    Post summary

    The provided text identifies CVE-2026-29796 as a WebSocket authentication bypass in an OCPP charging station management system, but offers no proof of exploitation, PoC, or mitigation details.

    0001042
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-29796: CRITICAL] Weak security in WebSocket endpoints allows unauthorized users to impersonate stations, manipulate data, and gain unauthorized control, leading to potential privilege escalation an...#cve,CVE-2026-29796,#cybersecurity https://cvefind.com/CVE-2026-29796

    Post summary

    The post discloses a critical WebSocket endpoint vulnerability that enables impersonation, data manipulation, and potential privilege escalation.

    0001056
    604 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29796 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. A… https://www.cve.org/CVERecord?id=CVE-2026-29796

    Post summary

    CVE-2026-29796 describes unauthenticated WebSocket endpoints that allow attackers to impersonate stations and alter data, with no available exploit, patch, or evidence of active exploitation.

    00000125
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-29796 - Critical WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated att... https://www.thehackerwire.com/vulnerability/CVE-2026-29796/ https://t.co/ev2AMapCVb

    Post summary

    CVE-2026-29796 is a critical flaw in WebSocket authentication that allows unauthenticated attackers to impersonate stations and manipulate backend data; no PoC or active exploitation evidence is provided.

    0000036
    138 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-29796: IG... OCPP WebSocket endpoints with zero auth = instant charging station takeover - every EV charger becomes your botnet node. #EVSec #OCPP #CriticalInfra. https://zerodaysignal.com/vulnerability/CVE-2026-29796 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A newly disclosed CVE-2026-29796 allows attackers to take over OCPP WebSocket endpoints without authentication, turning EV chargers into botnet nodes. While the vulnerability details are posted on zerodaysignal, no exploit tool or patch information is provided.

    0000061
    155 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appigleparking.fi---

Explore more