CVE-2026-54479Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-25); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-25: 2Mentions · 2026-06-26: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 106-2506-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-252
Disclosure1General1
2026-06-261
Disclosure1
Full discourse3 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-54479 - DoS in Websocket backend. Predictable session IDs allow auth bypass or resource exhaustion. #CVSS 7.3. No patch yet. Monitor systems closely. #infosec #cybersecurity #devsecops #devops #sysadmin More detailed info: https://www.valtersit.com/cve/CVE-2026-54479

    Post summary

    The post announces CVE‑2026‑54479, a DoS vulnerability in a websocket backend caused by predictable session IDs, with a CVSS score of 7.3. No patch, PoC, or exploit is provided, and the vulnerability is not reported to be actively exploited.

    0000088
    967 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-54479 The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. Thi… https://www.cve.org/CVERecord?id=CVE-2026-54479 ----- Traducción: CVE-2026-54479 El … http://infoflow.cloud`

    Post summary

    The tweet points to CVE‑2026‑54479 with a brief description and link to the CVE record, but does not mention PoCs, exploits, active use, or remedies.

    0000027
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54479 The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. Thi… https://www.cve.org/CVERecord?id=CVE-2026-54479

    Post summary

    The CVE details that a WebSocket backend uniquely associates sessions with charging station identifiers, yet it mistakenly permits multiple endpoints to share the same session identifier, potentially leading to concurrent session issues.

    00000655
    57.7K followersView on X

Explore more