A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.
History

Fri, 31 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title JWT Algorithm Validation Bypass in Siemens Opcenter X

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title JWT Algorithm Validation Bypass in Siemens Opcenter X

Fri, 24 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title JWT Algorithm Validation Bypass in Siemens Opcenter X

Mon, 20 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title JWT Algorithm Validation Failure Enables Full Account Takeover in Siemens Opcenter X

Thu, 16 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title JWT Algorithm Validation Failure Enables Full Account Takeover in Siemens Opcenter X

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2026-07-14T09:19:18.322Z

Updated: 2026-07-14T14:30:15.376Z

Reserved: 2026-06-22T13:17:54.241Z

Link: CVE-2026-56451

cve-icon Vulnrichment

Updated: 2026-07-14T14:26:46.824Z

cve-icon NVD

No data.

cve-icon Redhat

No data.