External risk intelligence

WebSocket Endpoint Authentication Bypass Allows Charging Station Impersonation

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-95102

The vulnerability involves WebSocket endpoints used for communication with charging stations, which are typically internet-facing by design to facilitate remote management and connectivity in distributed infrastructure.

Missing Authentication

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in certain systems involving WebSocket communication, potentially allowing unauthorized access to sensitive data or actions by impersonating charging stations. The lack of required authentication is a key factor, which could lead to privilege escalation and broader system compromise. The main concern is confirming relevance and exposure to our environment.

  • Unauthenticated access to charging station communications.
  • Risks unauthorized data access and system compromise.
  • Confirm relevance and exposure to our environment.

Attack Path

How an attacker could exploit the issue

An attacker can target the system by sending unauthenticated requests to WebSocket endpoints, which are exposed to the network. This allows them to impersonate legitimate charging stations. Successful exploitation could lead to unauthorized access to sensitive information or the execution of unintended actions within the system, potentially escalating privileges and impacting overall security.

  • No authentication needed for entry.
  • Triggered by sending unauthenticated WebSocket requests.
  • Risk of unauthorized access and actions.

Live Threat

Current exploitation, exposure, and threat context

The vulnerability could impact systems that use WebSocket endpoints for communication with charging stations. An unauthenticated attacker could exploit this by impersonating a charging station, potentially leading to unauthorized access to sensitive data or the ability to perform unauthorized actions within the system. When supported by the advisory, this could lead to privilege escalation.

  • System data and sensitive information.
  • Impersonating charging stations.
  • Unauthorized access and actions.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability affecting WebSocket endpoints requires immediate attention. The primary responsibility likely falls to the platform or infrastructure teams managing the charging station environment, in coordination with network and security teams to assess exposure. The first practical step is to identify all deployed charging station instances, confirm their reachability from external networks, and ascertain which are considered business-critical to prioritize remediation efforts.

  • Platform and network teams should own.
  • Verify external reachability and criticality.
  • Plan targeted remediation or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the software affected by CVE-2026-95102?

This CVE affects systems that use WebSocket endpoints to facilitate communication with electric vehicle charging stations. These components serve as the bridge between distributed charging hardware and central management software, allowing for remote monitoring, command execution, and data exchange necessary to operate a charging network.

How does this vulnerability work?

The flaw is classified as a Missing Authentication for Critical Function (CWE-306). It means the system's WebSocket endpoints fail to verify the identity of incoming connections. Because there is no authentication gate, an attacker can connect directly to the service and pretend to be a legitimate charging station to send malicious commands or access system data.

Do I need to do anything specific to trigger this bug?

No complex setup is required. An attacker only needs to send a crafted request to the vulnerable WebSocket endpoint. This vulnerability is not triggered by user interaction or specific account permissions, as the system does not verify identity at any point during the initial connection handshake.

Is my system at risk?

According to Halo Surface Signal, this risk is very likely if your charging station infrastructure is internet-facing. Because these systems are typically designed to connect to the web for remote management, they are often reachable by external actors. Systems isolated from the public internet have a reduced risk profile compared to those exposed directly.

How should I begin addressing CVE-2026-95102?

Start by identifying all charging station instances within your infrastructure and determining which ones are reachable from the internet. Prioritize these internet-facing systems for review, as they present the highest risk. Coordinate with your platform and network security teams to verify their current communication configurations and assess the potential impact on your environment.

References