PatchSiren cyber security CVE debrief
CVE-2026-20781 Unknown Vendor CVE debrief
CVE-2026-20781 is a critical authentication flaw in CloudCharge's OCPP WebSocket endpoints. Because no authentication is required, an attacker who knows or discovers a charging-station identifier can impersonate a legitimate charger, exchange OCPP commands, and tamper with backend-reported data. The likely impact includes unauthorized control of charging infrastructure, privilege escalation, and corruption of operational data.
- Vendor
- Unknown Vendor
- Product
- CloudCharge cloudcharge.se vers:all/*
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-26
- Original CVE updated
- 2026-02-26
- Advisory published
- 2026-02-26
- Advisory updated
- 2026-02-26
Who should care
Operators of CloudCharge-managed EV charging stations, OT/ICS security teams, backend integrators using OCPP, and asset owners responsible for station identity and access control.
Technical summary
CISA's CSAF advisory states that the OCPP WebSocket endpoint lacks proper authentication. An unauthenticated remote actor can connect using a known or discovered station identifier and then issue or receive OCPP commands as if it were a legitimate charger. The advisory describes resulting risks as privilege escalation, unauthorized infrastructure control, and corruption of charging-network data reported to the backend. CISA lists the issue as CVSS v3.1 9.4 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L) and SSVCv2 E:N/A:Y.
Defensive priority
Urgent. This is network-reachable, requires no credentials, and can directly affect charger control and backend data integrity. Treat it as a high-priority exposure reduction issue until vendor guidance or a fix is available.
Recommended defensive actions
- Restrict access to the OCPP WebSocket endpoint to trusted management networks and known charging-station paths only.
- Review whether station identifiers are exposed or predictable, and strengthen identity validation and backend authorization checks where possible.
- Monitor for unusual OCPP sessions, unexpected station IDs, and backend records that suggest charger impersonation or data tampering.
- Segment charging infrastructure from general-purpose networks to reduce the blast radius of unauthorized station access.
- Apply vendor-provided remediation or compensating controls as soon as they are available, and follow the contact path listed in the advisory if you need vendor coordination.
Evidence notes
All material facts are taken from CISA CSAF advisory ICSA-26-057-03 for CVE-2026-20781 and the linked CISA reference pages. The supplied advisory text states that CloudCharge did not respond to CISA's coordination request. The vendor/product naming in the corpus is preserved as published, but the vendor identity confidence is low and flagged for review. No exploit instructions or unsupported claims are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-20781 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-20781
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-20781 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20781
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.