CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Hydro-Quebec EV-charging: no auth-attempt throttling -> DoS (CVSS 7.5), ICSA-26-188-01

cve · CVE-2026-42952 single-source-national-cert

Coverage
1
first 2026-07-08 → last 2026-07-08
Latest activity
2026-07-08
CISA ICSA-26-188-01: unauthenticated OCPP WebSocket in an EV-charging backend, a transferable lesson for any…
Peak priority
notable
1 notable
Targets
energy
sectors: energy, transport
Sources cited
2
2 hosts

Action items (2)

Do-now tasks recorded on the entries about CVE-2026-42952, newest first. Check the date before acting on an older one.

  • Any OCPP central-system operator: verify the WebSocket upgrade enforces mutual TLS or HTTP Basic Auth per OCPP Security Profile 2/3 rather than accepting unauthenticated ws:// upgrades.
    2026-07-08CVE-2026-20744 +2
  • Rate-limit repeated OCPP BootNotification/Authorize attempts per source, and reject duplicate concurrent connections claiming the same ChargePointId (closes the session-exhaustion class); since charge-point hardware carries no endpoint agent, detect on backend session-churn/connection-count anomalies per charge-point ID.
    2026-07-08CVE-2026-20744 +2

Defender insights

What each entry about CVE-2026-42952 tells a defender to do, newest first.

2026-07-08NOTABLECISA ICSA-26-188-01: unauthenticated OCPP WebSocket in an EV-charging backend, a transferable lesson for any charge-point operator

Story timeline

  1. 2026-07-08CVE-2026-20744, Hydro-Québec EV-charging backend: unauthenticated OCPP WebSocket endpoint enables privilege escalation
    trending-vulnerabilitiesCISA ICSA-26-188-01: unauthenticated OCPP WebSocket in an EV-charging backend, a transferable lesson for any charge-point operator
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-08/cve-2026-20744-hydro-quebec-ocpp-unauth-websocket · ATT&CK page ↗

Entries about Hydro-Quebec EV-charging: no auth-attempt throttling -> DoS (CVSS 7.5), ICSA-26-188-01 (1)

2026-07-08 · view entry permalink →

CVE-2026-20744, Hydro-Québec EV-charging backend: unauthenticated OCPP WebSocket endpoint enables privilege escalation

CISA published ICS advisory ICSA-26-188-01 for the backend of Hydro-Québec's "Le Circuit Électrique" EV-charging network, disclosing three flaws reported by an anonymous researcher (CISA, 2026-07-07). The headline flaw, CVE-2026-20744 (CVSS v3.1 9.8, CWE-284 Improper Access Control), is in the charging-station WebSocket endpoint that speaks OCPP (Open Charge Point Protocol, the industry-standard charge-point-to-backend management protocol): the endpoint accepts connections with no authentication, letting a remote unauthenticated actor escalate privileges against the backend (T1190). Two companion flaws compound the exposure, CVE-2026-42952 (CVSS 7.5, CWE-307, no throttling on repeated authentication attempts → brute-force/DoS) and CVE-2026-44383 (CVSS 7.5, CWE-613, the backend allows multiple simultaneous connections under the same charging-station identifier, enabling session-exhaustion DoS via duplicate OCPP clients). There is no version-numbered software patch; Hydro-Québec's remediation is operational (OCPP has been disabled on most charging stations and authentication added for the remainder still using it) and CISA reports no known public exploitation (CISA CSAF, 2026-07-07).

The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

CISA (ICS Advisory ICSA-26-188-01) 2026-07-07
vulnerability08 Jul 20:35Zsingle-source · national CERTOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • cisa.gov1 (50%)
  • raw.githubusercontent.com1 (50%)