High-severity vulnerabilities were disclosed in OpenClaw and CTEK Chargeportal, with both flaws tied to insecure WebSocket handling that can let attackers gain unauthorized control. In CVE-2026-22172, OpenClaw versions prior to 2026.3.12 fail to properly bind authorized scopes in shared-token or password-authenticated WebSocket sessions, allowing a low-privileged user to self-assign elevated permissions such as operator.admin and perform admin-only gateway operations. The issue is classified as CWE-862 and carries a CVSS v3.1 score reflecting high impact to confidentiality, integrity, and availability.
In CVE-2026-25192, CTEK Chargeportal exposes WebSocket endpoints that do not properly authenticate critical functions, enabling an unauthenticated attacker to impersonate EV charging stations by using a known or discovered station identifier. That access can be used to send or receive OCPP commands as a legitimate charger, potentially leading to unauthorized control of charging infrastructure, privilege escalation, and corruption of backend charging data. The flaw is tracked as CWE-306 and is covered in CISA advisory ICSA-26-078-06, with impact rated high for confidentiality and integrity.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A high-severity missing-authentication vulnerability in CTEK Chargeportal was disclosed as CVE-2026-25192. The issue allows unauthenticated attackers to impersonate charging stations over OCPP WebSocket endpoints using a known or discovered station identifier and manipulate charging infrastructure traffic.
A high-severity authorization bypass in OpenClaw versions prior to 2026.3.12 was disclosed as CVE-2026-22172. The flaw allows low-privileged shared-token or password-authenticated users to self-assign elevated scopes such as operator.admin through improperly bound WebSocket authorization scopes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.