What is CVE-2026-44098?
CVE-2026-44098 is a vulnerability that allows an unauthenticated remote attacker controlling the OCPP backend via a firewall-bypass to perform OS command injection. This can lead to arbitrary command execution as the limited user 'charx-oa' and potential interruption of the charging process. Mitigation involves applying patches and reviewing network-level restrictions for the OCPP infrastructure.
Azərbaycanca: CVE-2026-44098 zəifliyi, firewall-bypass vasitəsilə OCPP backend-ini ələ keçirən autentifikasiya olunmamış uzaqdan hücumçuya OS command injection etməyə imkan verir. Bu, 'charx-oa' məhdud istifadəçisi kimi ixtiyari əmrlərin icrasına və enerji doldurma prosesinin dayandırılmasına səbəb ola bilər. OCPP infrastrukturunu qorumaq üçün müvafiq yamaqlar tətbiq edilməli və şəbəkə səviyyəsində məhdudiyyətlər yoxlanılmalıdır.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
What does the CVE-2026-44098 vulnerability allow a remote attacker to do?
This vulnerability allows an unauthenticated attacker controlling the OCPP backend via a firewall-bypass to perform OS command injection. As a result, arbitrary commands can be executed as the limited user 'charx-oa'.
What measures should be taken to mitigate the impact of CVE-2026-44098?
Mitigation involves applying appropriate patches and reviewing network-level restrictions for the OCPP infrastructure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.