Skip to content
SiemensCVE-2026-56451

Siemens Opcenter X: authentication bypass

Critical10.0CVE-2026-56451 · Published Jul 14, 2026 · updated Jul 15, 2026

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.

Siemens advisory

Affected versions

PackageAffectedFixed in
Opcenter X
Product
< V2604V2604
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-347

More Siemens advisories

All Siemens
Advisory
Siemens SIMATIC S7-PLCSIM Advanced: denial of service
Medium6.0Jul 14
Siemens COMOS: untrusted search path
High8.5Jul 14
Siemens CPCI85 Central Processing/Communication: denial of service
High7.1Jul 9
Siemens CPCI85 Central Processing/Communication: code execution
High8.4Jul 9
Siemens CPCI85 Central Processing/Communication: insecure default
Medium6.3Jul 9
Siemens CPCI85 Central Processing/Communication: authenticated attacker could...
High8.6Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.