CVE-2026-40702
Last modified
CVE-2026-40702 is a critical-severity vulnerability rated 9.4/10 on the CVSS scale. WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-40702?
How severe is CVE-2026-40702?
How do I fix CVE-2026-40702?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40690The asset dependency graph did not restrict nodes by the vie…4.3
- CVE-2026-40691In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt…7.5
- CVE-2026-40698A vulnerability exists in BIG-IP and BIG-IQ systems where a …8.7
- CVE-2026-40699A vulnerability exists in the undisclosed pages in the Confi…7.1
- CVE-2026-4070The Alfie – Feed Plugin plugin for WordPress is vulnerable t…4.3
- CVE-2026-40701NGINX Plus and NGINX Open Source have a vulnerability in the…6.3
- CVE-2026-40703A cross-site request forgery (CSRF) vulnerability exists in …5.4
- CVE-2026-40706In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflo…8.4
- CVE-2026-4071The BirdSeed plugin for WordPress is vulnerable to Cross-Sit…4.3
- CVE-2026-40711Dell Dell Container Storage Modules, version(s) csi-powersto…8
- CVE-2026-40712Dell PowerProtect Data Manager, versions prior to 20.2.0.0, …7.2
- CVE-2026-40713Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, con…6.1
Are you affected by CVE-2026-40702?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
