CVE-2026-56451: exploitation status and patch state

CVE-2026-56451 · CVSS 10.0 CRITICAL · EPSS <1%

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.

Is CVE-2026-56451 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-56451

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.