CVE-2026-44383

HIGH

Hydro-Québec Le Circuit Electrique charging station backend Insufficient Session Expiration

Title source: cna
STIX 2.1

Description

Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.

Scores

CVSS v3 7.5
EPSS 0.0045
EPSS Percentile 36.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (1)
Hydro-Québec/Le Circuit Electrique charging station backend < June_2026
Published Jul 10, 2026
Tracked Since Jul 11, 2026