Vulnerability intelligence
CVE-2026-56451
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.
CVSS Score
10
Critical
EPSS — Exploit Probability
0.4%
Riskier than 31% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jul 20, 2026 · latest Jul 20, 2026
Coverage timeline
-
CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Accesssecurityonline.info · Jul 20, 2026