---
schema: 1
kind: vulnerability
title: "CVE-2026-20744 — Hydro-Québec EV-charging backend: unauthenticated OCPP WebSocket endpoint enables privilege escalation"
headline: "CISA ICSA-26-188-01: unauthenticated OCPP WebSocket in an EV-charging backend — a transferable lesson for any charge-point operator"
summary: >
  CISA advisory ICSA-26-188-01 discloses an unauthenticated OCPP WebSocket endpoint (CVE-2026-20744, CVSS 9.8) in the backend of Hydro-Québec's EV-charging network, plus two companion DoS flaws. Hydro-Québec's fix is operational (OCPP disabled / auth added), not a version patch. The transferable weakness — an unauthenticated OCPP management channel — applies to any charge-point operator, including Swiss/EU public charging infrastructure.
discovered_at: "2026-07-08T20:35:00Z"
event_date: 2026-07-07
run_id: 2026-07-08T2009Z-intel
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - ot-ics
  - auth-bypass
  - dos
  - no-patch
regions:
  - global
sectors:
  - energy
  - transport
entities: []
cves:
  - id: CVE-2026-20744
    cvss: "9.8"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - mitigation-only
    affected: "Hydro-Québec charging backend < June 2026"
    fixed: "operational mitigation (OCPP disabled / authentication added)"
  - id: CVE-2026-42952
    cvss: "7.5"
    epss: null
    type: dos
    vector: zero-click
    auth: pre-auth
    status:
      - mitigation-only
    affected: "Hydro-Québec charging backend < June 2026"
    fixed: "operational mitigation"
  - id: CVE-2026-44383
    cvss: "7.5"
    epss: null
    type: dos
    vector: zero-click
    auth: pre-auth
    status:
      - mitigation-only
    affected: "Hydro-Québec charging backend < June 2026"
    fixed: "operational mitigation"
sources:
  - url: "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01"
    publisher: "CISA (ICS Advisory ICSA-26-188-01)"
    date: "2026-07-07"
    role: primary
  - url: "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-01.json"
    publisher: "CISA CSAF machine-readable advisory"
    date: "2026-07-07"
    role: corroborating
closed_sources: []
evidence:
  - quote: "The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation."
    publisher: "CISA (ICS Advisory ICSA-26-188-01)"
  - quote: "No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time."
    publisher: "CISA (ICS Advisory ICSA-26-188-01)"
verification: single-source-national-cert
sourcing_note: "Primary is CISA's own ICS advisory (national-authority carve-out); same-day rewrites by other outlets are not independent corroboration. The machine-readable CSAF JSON is the same authority's structured record."
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "Any OCPP central-system operator: verify the WebSocket upgrade enforces mutual TLS or HTTP Basic Auth per OCPP Security Profile 2/3 rather than accepting unauthenticated ws:// upgrades."
  - "Rate-limit repeated OCPP BootNotification/Authorize attempts per source, and reject duplicate concurrent connections claiming the same ChargePointId (closes the session-exhaustion class); since charge-point hardware carries no endpoint agent, detect on backend session-churn/connection-count anomalies per charge-point ID."
migrated_from: null
---

CISA published ICS advisory ICSA-26-188-01 for the backend of Hydro-Québec's "Le Circuit Électrique" EV-charging network, disclosing three flaws reported by an anonymous researcher ([CISA, 2026-07-07](https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01)). The headline flaw, CVE-2026-20744 (CVSS v3.1 9.8, CWE-284 Improper Access Control), is in the charging-station WebSocket endpoint that speaks OCPP (Open Charge Point Protocol, the industry-standard charge-point-to-backend management protocol): the endpoint accepts connections with no authentication, letting a remote unauthenticated actor escalate privileges against the backend (`T1190`). Two companion flaws compound the exposure — CVE-2026-42952 (CVSS 7.5, CWE-307, no throttling on repeated authentication attempts → brute-force/DoS) and CVE-2026-44383 (CVSS 7.5, CWE-613, the backend allows multiple simultaneous connections under the same charging-station identifier, enabling session-exhaustion DoS via duplicate OCPP clients). There is no version-numbered software patch; Hydro-Québec's remediation is operational — OCPP has been disabled on most charging stations and authentication added for the remainder still using it — and CISA reports no known public exploitation ([CISA CSAF, 2026-07-07](https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-01.json)). **Defender takeaway:** the advisory scopes to a single Canadian operator, but the underlying weakness class — an unauthenticated OCPP WebSocket management channel — is a protocol-implementation pattern relevant to every EV-charging network operator, and OCPP is the near-universal charge-point management standard across Swiss/EU public charging infrastructure; the fix is a configuration/security-profile decision (enforce OCPP Security Profile 2/3, one session per charge-point identity), and because the hardware carries no agent, monitoring is necessarily backend/network-telemetry-based.
