Back to Feed
VulnerabilitiesMar 3, 2026

Everon OCPP Backends

Everon OCPP Backends, a critical infrastructure charging station management system, contains four critical-to-high severity vulnerabilities affecting all versions of api.everon.io. These flaws include missing WebSocket authentication (CVE-2026-26288), lack of rate limiting on authentication attempts (CVE-2026-24696), session hijacking via predictable identifiers (CVE-2026-20748), and exposed credentials on public mapping platforms (CVE-2026-27027), which could allow attackers to gain unauthorized administrative control over charging stations or disrupt services. Everon has shut down its platform as of December 1st, 2025.

Summary

Everon OCPP Backends, a critical infrastructure charging station management system, contains four critical-to-high severity vulnerabilities affecting all versions of api.everon.io. These flaws include missing WebSocket authentication (CVE-2026-26288), lack of rate limiting on authentication attempts (CVE-2026-24696), session hijacking via predictable identifiers (CVE-2026-20748), and exposed credentials on public mapping platforms (CVE-2026-27027), which could allow attackers to gain unauthorized administrative control over charging stations or disrupt services. Everon has shut down its platform as of December 1st, 2025.

Indicators of Compromise

  • cve — CVE-2026-26288
  • cve — CVE-2026-24696
  • cve — CVE-2026-20748
  • cve — CVE-2026-27027
  • domain — api.everon.io