Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-20744: Unauthenticated Access to Charging Station Websocket Endpoint
CVE-2026-20744
Summary
The charging station's websocket endpoint doesn't require authentication, allowing unauthorized users to potentially gain higher access levels. This could lead to unauthorized access to sensitive charging station functions. To fix this, ensure proper authentication is implemented for the websocket endpoint.
Original title
The charging station websocket endpoint accepts connections without
proper authentication, which could lead to privilege escalation.
Original description
The charging station websocket endpoint accepts connections without
proper authentication, which could lead to privilege escalation.
proper authentication, which could lead to privilege escalation.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-284
Improper Access Control
Published: 10 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026