As cited
Copy frozen at (site build).
vulnerabilities
Siemens Opcenter X
Siemens Opcenter X versions prior to V2604 contain a critical authentication bypass vulnerability (CVE-2026-56451) in JSON Web Token (JWT) validation that allows unauthenticated attackers to forge tokens and impersonate any user, including administrators. Siemens has released version V2604 with a fix and recommends immediate updates for affected deployments worldwide. The vulnerability carries a CVSS base score of 10.0 and affects critical manufacturing infrastructure.
Why it matters: Manufacturing organizations running Opcenter X below V2604 face immediate risk of complete unauthorized system access and must prioritize patching to V2604 or later to prevent attackers from taking full control of production systems.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Siemens Opcenter X
Siemens Opcenter X versions prior to V2604 contain a critical authentication bypass vulnerability (CVE-2026-56451) in JSON Web Token (JWT) validation that allows unauthenticated attackers to forge tokens and impersonate any user, including administrators. Siemens has released version V2604 with a fix and recommends immediate updates for affected deployments worldwide. The vulnerability carries a CVSS base score of 10.0 and affects critical manufacturing infrastructure.
Why it matters: Manufacturing organizations running Opcenter X below V2604 face immediate risk of complete unauthorized system access and must prioritize patching to V2604 or later to prevent attackers from taking full control of production systems.
- Source published
- First seen by Cybersecurity Tracker