External risk intelligence

CHARX OCPP Agent Missing Authentication Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-44101

The vulnerability affects an OCPP Agent service, which is designed to facilitate communication between electric vehicle charging stations and backend management systems. These services typically operate as network-accessible gateways or management endpoints to ensure connectivity for distributed infrastructure, making them commonly reachable in operational deployments.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the CHARX OCPP Agent service, which could allow an unauthenticated remote attacker to reconfigure the backend connection. This may lead to a denial-of-service condition or the disclosure of confidential data. The main concern is confirming relevance and exposure, as the service is network-accessible and commonly used for electric vehicle charging station management.

  • Unauthenticated access can alter connections.
  • Matters if charging stations are managed.
  • Confirm relevance and exposure to operational impact.

Attack Path

How an attacker could exploit the issue

An unauthenticated remote attacker can exploit this vulnerability by directly accessing the CHARX OCPP Agent service over the network. Since the service lacks proper authentication, the attacker can send specially crafted requests to reconfigure its backend connection. This allows the attacker to disrupt normal operations, leading to a denial-of-service condition, and potentially intercept or disclose sensitive confidential data.

  • No authentication is required to access.
  • Reconfiguring the backend connection triggers the vulnerability.
  • Leads to data disclosure and denial of service.

Live Threat

Current exploitation, exposure, and threat context

The CHARX OCPP Agent service, when accessed remotely and without authentication, could allow an attacker to alter its backend connection settings. This manipulation may result in a denial-of-service condition and the disclosure of confidential data to the attacker.

  • Service configuration and backend connection.
  • Unauthenticated remote attacker reconfiguration.
  • Denial-of-service and data disclosure.

Operational Fix

Recommended remediation, mitigation, and detection steps

The CHARX OCPP Agent service, which handles communication for electric vehicle charging stations, is susceptible to reconfiguring its backend connection due to missing authentication. This vulnerability can lead to denial-of-service conditions and the disclosure of confidential data to unauthenticated remote attackers. Identifying instances of this service, assessing their reachability and criticality, and assigning an owner for remediation planning are the immediate priorities.

  • Ownership: Platform or infrastructure teams.
  • Verify: Service reachability and data criticality.
  • Action: Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the CHARX OCPP Agent?

The CHARX OCPP Agent is a software component that facilitates communication between electric vehicle charging stations and their backend management systems. It acts as a specialized gateway or interface, allowing infrastructure operators to manage charging equipment, monitor status, and handle operational data remotely. By managing these backend connections, the agent ensures that distributed charging stations remain integrated and functional within an enterprise network.

What does CWE-306 mean for CVE-2026-44101?

CWE-306 refers to a Missing Authentication for Critical Function weakness. In the context of CVE-2026-44101, this means the software performs a sensitive operation—specifically reconfiguring backend connections—without first verifying the identity of the user or system making the request. Because the service trusts all incoming connection requests by default, it fails to prevent unauthorized parties from altering its fundamental operational settings.

How is this vulnerability triggered?

An attacker triggers this vulnerability by sending specially crafted network requests directly to the CHARX OCPP Agent service. Because the service lacks authentication, it processes these unauthorized instructions to modify backend settings immediately. It is important to note that this bug is not triggered by standard, authorized monitoring traffic; it requires deliberate, unauthorized interaction with the configuration interface of the service to achieve the reported impact.

Why is this CVE considered relevant for my network?

According to Halo Surface Signal, this service is frequently deployed as a network-accessible gateway to support distributed charging infrastructure, often making it reachable from broader network segments. If your charging management systems are accessible over a network, this vulnerability is highly relevant because it bypasses traditional security barriers, allowing remote actors to disrupt service or access sensitive data without needing valid credentials.

What should I do if I run this software?

If you manage CHARX OCPP Agent instances, your first step is to identify where this service is active and confirm its network reachability. Once localized, prioritize assessing the criticality of the data it handles. Engage your infrastructure or platform teams to establish ownership and initiate a risk-based remediation plan, focusing on restricting unauthorized access to these management endpoints until a formal update or configuration hardening is available.

References