Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-56451: Opcenter X: Unauthenticated User Impersonation via JWT Forgery

CVE-2026-56451
Summary

Opcenter X versions prior to V2604 do not properly check JWT headers. This allows an attacker to create fake user identities, potentially gaining full access to the application. Update to version V2604 or later to fix this issue.

Original title
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allo...
Original description
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header.
This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.
nvd CVSS3.1 10.0
nvd CVSS4.0 10.0
Vulnerability type
CWE-347 Improper Verification of Cryptographic Signature
Published: 14 Jul 2026 · Updated: 20 Jul 2026 · First seen: 14 Jul 2026