securityonline.info 7/20/2026, 2:51:23 PM · external

CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Access

CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Access
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

SIEMENS has identified a critical authentication bypass vulnerability in Opcenter X, tracked as CVE-2026-56451, which has a maximum severity score of 10.0 on CVSS. The flaw affects all versions prior to V2604, allowing unauthenticated remote attackers to forge JSON Web Tokens (JWTs) and impersonate users, including administrators. No confirmed exploitation has been reported, but users are urged to update to V2604 immediately to mitigate risks. The root cause of the flaw is improper verification of cryptographic signatures, leading to severe potential consequences if left unaddressed.

View Primary Source Via securityonline.info

Article by CyberSIXT