CVE-2026-56451

CRITICAL

View CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new...

Affects 0 products across 1 vendor.

CVSS 3.110.0
CVSS v410.0
EPSS0.3%
Percentile23th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-347: CWE-347
Related Attack Patterns (CAPEC)
CAPEC-463 Padding Oracle Crypto Attack
via CWE-347
CAPEC-475 Signature Spoofing by Improper Validation
via CWE-347

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical severity vulnerability (CVE-2026-56451) affects the target system. A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitra...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-56451?
A critical severity vulnerability (CVE-2026-56451) affects the target system. A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitra...
What is the CVSS score for CVE-2026-56451?
CVE-2026-56451 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.3%.
Is CVE-2026-56451 actively exploited?
No confirmed active exploitation of CVE-2026-56451 as of 2026-07-22.
How do I remediate CVE-2026-56451?
Apply vendor patches for CVE-2026-56451. Monitor Siemens advisories.
What systems are affected by CVE-2026-56451?
CVE-2026-56451 affects: Siemens.
Vulnerability Details
CVE IDCVE-2026-56451
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2026-07-21
Last Modified2026-07-21
Weakness (CWE)
SourceNVD
Official Description

View CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version. The following versions of Siemens Opcenter X are affected: Opcenter X vers:intdot/<2604 CVSS Vendor Equipment Vulnerabilities v3 10 Siemens Siemens Opcenter X Improper Verification of Cryptographic Signature Background Critical Inf

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Siemens &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 13 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Siemens
CVE-2024-45032 10.0 A vulnerability has been identified in Industrial Edge Management Pro (All ve... CVE-2000-0964 10.0 Buffer overflow in the web administration service for the HiNet LP5100 IP-pho... CVE-2007-1917 10.0 Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library... CVE-2025-40805 10.0 Affected devices do not properly enforce user authentication on specific API ... CVE-2007-1916 10.0 Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and...
View all Siemens CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →