Forged JWTs Can Impersonate Opcenter X Admins

Opcenter X below V2604 treats a forged JWT as a real login, so an attacker can step into any user’s session, including admin. The broken check is in the token’s algorithm validation, which means standard access controls fall away once the app accepts the token. CISA and Siemens have published CVE-2026-56451 for Siemens Opcenter X < V2604. Siemens says V2604 fixes the issue, and the flaw affects Opcenter X deployments in critical manufacturing environments.

Part of the PlainSec briefing for 2026-07-21

Sources