A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header.
This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jul 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | JWT Algorithm Validation Bypass in Siemens Opcenter X |
Tue, 28 Jul 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | JWT Algorithm Validation Bypass in Siemens Opcenter X |
Fri, 24 Jul 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | JWT Algorithm Validation Bypass in Siemens Opcenter X |
Mon, 20 Jul 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | JWT Algorithm Validation Failure Enables Full Account Takeover in Siemens Opcenter X |
Thu, 16 Jul 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | JWT Algorithm Validation Failure Enables Full Account Takeover in Siemens Opcenter X |
Tue, 14 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Jul 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application. | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published: 2026-07-14T09:19:18.322Z
Updated: 2026-07-14T14:30:15.376Z
Reserved: 2026-06-22T13:17:54.241Z
Link: CVE-2026-56451
Updated: 2026-07-14T14:26:46.824Z
No data.
No data.