Siemens disclosed CVE-2026-56451, a critical authentication-bypass vulnerability in Opcenter X caused by improper validation of the algorithm specified in a JSON Web Token (JWT) header. The flaw affects all versions earlier than V2604 and allows an unauthenticated remote attacker to forge arbitrary JWTs, bypass authentication, impersonate any user including administrators, and potentially obtain full unauthorized access to the application.
The issue is classified as CWE-347 and was assigned a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, with reporting indicating a maximum severity score of 10.0 under both CVSS 3.1 and 4.0. Siemens identified V2604 as the remediation release through its ProductCERT advisory, and no active exploitation was reported at disclosure, although the attack class is considered highly exploitable because JWT algorithm confusion techniques are well known and broadly tooled.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Siemens provided Opcenter X V2604 as the remediation for CVE-2026-56451. The disclosure also stated that no active exploitation had been reported at the time of release.
Siemens disclosed a critical JWT algorithm confusion vulnerability in Opcenter X, tracked as CVE-2026-56451. The flaw affects all versions earlier than V2604 and could let an unauthenticated remote attacker forge JWTs, bypass authentication, and impersonate users including administrators.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcethreataft.com
Open sourcecert-portal.siemens.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.