SiemensCVE-2026-56451
Siemens Opcenter X: authentication bypass
Critical10.0CVE-2026-56451 · Published Jul 14, 2026 · updated Jul 15, 2026
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Opcenter X Product | < V2604 | V2604 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-347
More Siemens advisories
All Siemens| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | Siemens SIMATIC S7-PLCSIM Advanced: denial of service | Medium6.0 | No fix yet |
| Jul 14 | Siemens COMOS: untrusted search path | High8.5 | V10.4.5.0.2+9 more |
| Jul 9 | Siemens CPCI85 Central Processing/Communication: denial of service | High7.1 | V26.20+1 more |
| Jul 9 | Siemens CPCI85 Central Processing/Communication: code execution | High8.4 | V26.20+1 more |
| Jul 9 | Siemens CPCI85 Central Processing/Communication: insecure default | Medium6.3 | V26.20+1 more |
| Jul 9 | Siemens CPCI85 Central Processing/Communication: authenticated attacker could... | High8.6 | V26.20+1 more |