SIEMENS has identified a critical authentication bypass vulnerability in Opcenter X, tracked as CVE-2026-56451, which has a maximum severity score of 10.0 on CVSS. The flaw affects all versions prior to V2604, allowing unauthenticated remote attackers to forge JSON Web Tokens (JWTs) and impersonate users, including administrators. No confirmed exploitation has been reported, but users are urged to update to V2604 immediately to mitigate risks. The root cause of the flaw is improper verification of cryptographic signatures, leading to severe potential consequences if left unaddressed.
CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Access
CyberSIXT Evidence Panel
Article by CyberSIXT