Opcenter X below V2604 treats a forged JWT as a real login, so an attacker can step into any user’s session, including admin. The broken check is in the token’s algorithm validation, which means standard access controls fall away once the app accepts the token.
CISA and Siemens have published CVE-2026-56451 for Siemens Opcenter X < V2604. Siemens says V2604 fixes the issue, and the flaw affects Opcenter X deployments in critical manufacturing environments.