Junglewise Threat Intelligence

CVE-2026-20744: Hydro-Québec Le Circuit Electrique auth bypass in charging station backend

CVE-2026-20744 · Severity: critical · CVSS 9.8 · Published 2026-07-10

Technologies: Hydro-Québec Le Circuit Electrique charging station backend. Vendors: Hydro-Québec.

Executive brief

The backend system for Hydro-Québec's electric vehicle charging network contains a security flaw where its communication interface does not properly verify user identity. This could allow an unauthorized person to gain administrative control over the charging station management system. Such an exploit could lead to service disruptions, unauthorized access to charging data, or manipulation of the charging infrastructure.

Technical details

The vulnerability (CWE-284) exists in the WebSocket endpoint of the charging station backend, which fails to implement proper authentication for incoming connections. An unauthenticated remote attacker can connect to this endpoint and potentially escalate privileges within the system. The flaw specifically impacts the Open Charge Point Protocol (OCPP) communications. Hydro-Québec has mitigated the risk by disabling OCPP on the majority of stations and implementing new authentication systems for those still requiring it. The issue affects versions released prior to June 2026.

Affected products

  • Hydro-Québec Le Circuit Electrique charging station backend Before June 2026

Timeline

  • 2026-07-07: advisory: Initial publication by CISA (ICSA-26-188-01)
  • 2026-07-10: disclosed: CVE-2026-20744 published to NVD

References

Related threats