Security & Threat Intelligence · 21.07.2026, 21:21 UTC
Siemens Opcenter X
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories · CISA ICS Advisories ↗ |
| Veröffentlicht | 21.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-56451. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version. The following versions of Siemens Opcenter X are affected:
Opcenter X vers:intdot/<2604
CVSS Vendor Equipment Vulnerabilities
v3 10 Siemens Siemens Opcenter X Improper Verification of Cryptographic Signature
Background
Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-56451
Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application. View CVE Details
Affected Products Siemens Opcenter X
Vendor:Siemens Product Version:Opcenter X < V2604 Product Status:known_affected
Remediations Vendor fixUpdate to V2604 or later versionhttps://support.sw.siemens.com/product/206159703/
Relevant CWE: CWE-347 Improper Verification of Cryptographic Signature
Metrics
CVSS Version Base Score Base Severity Vector String
3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Acknowledgments
Siemens ProductCERT reported this vulnerability to CISA.
General Recommendations As a general security measure, Siemens strongly …