Vulnerability Description
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-44098?
CVE-2026-44098 is a vulnerability with a CVSS score of 8.6 (HIGH). This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands...
How severe is CVE-2026-44098?
CVE-2026-44098 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44098?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.