- CVE: CVE-2026-56451
- CVSS: 10.0 (Critical · CVSSv3)
- Product: Siemens Opcenter X
- Affected: < V2604
- Impact: A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications...
- Status: No confirmed exploitation yet
- Patched in: V2604
- EPSS: 0.4% (30-day)
- Action: Update to V2604 now
TL;DR
Siemens has patched a maximum-severity Opcenter X authentication bypass, tracked as CVE-2026-56451. The flaw scores 10.0 on both CVSS 3.1 and CVSS 4.0 scales. An unauthenticated remote attacker can forge JSON Web Tokens to impersonate any user, including administrators.
Why It Matters
Opcenter X is a cloud-based manufacturing operations management platform. It coordinates production data across plants, so unauthorized access could expose sensitive operations. According to the Siemens advisory, the flaw lets an attacker “gain full unauthorized access to the application.” A perfect-10 score with no authentication required leaves defenders little room to wait. As a result, this Opcenter X authentication bypass demands priority attention from OT teams.
How the Attack Works
The root cause maps to CWE-347, improper verification of a cryptographic signature. Affected applications do not properly validate the algorithm named in the JWT header. Consequently, a remote attacker can forge arbitrary tokens and bypass authentication. From there, the attacker can impersonate any account and seize administrative control. This report describes the mechanism only and includes no exploit steps.
Affected Versions
The authentication bypass affects all Opcenter X versions before V2604. Siemens fixed the issue in V2604 and later releases.
Exploitation Status
Siemens found the flaw internally, and its advisory reports no active exploitation. Likewise, no public proof-of-concept has surfaced at the time of writing.
Patch and Mitigation Steps
Update Opcenter X to V2604 or a later version without delay. In addition, restrict network access to the platform using Siemens’ operational guidelines for industrial security.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.