Junglewise Threat Intelligence

CVE-2026-44383: Hydro-Québec Le Circuit Electrique denial of service in charging backend

CVE-2026-44383 · Severity: high · CVSS 7.5 · Published 2026-07-10

Technologies: Hydro-Québec Le Circuit Electrique charging station backend. Vendors: Hydro-Québec.

Executive brief

The Hydro-Québec Le Circuit Electrique charging station backend, which manages electric vehicle charging infrastructure, is vulnerable to a denial-of-service attack. An attacker can connect multiple malicious clients using the same charging station ID to overwhelm the system. This could lead to service outages, preventing legitimate users from using charging stations or disrupting the management of the charging network.

Technical details

The Hydro-Québec Le Circuit Electrique charging station backend fails to properly restrict concurrent sessions using the same charging station identifier. This vulnerability, classified as Insufficient Session Expiration (CWE-613), allows a remote attacker to deploy multiple instances of malicious Open Charge Point Protocol (OCPP) clients using a single ID. By flooding the backend with these duplicate connections, an attacker can exhaust system resources and cause a denial-of-service (DoS) condition. The vulnerability is reachable over the network without authentication. Hydro-Québec has mitigated the risk by disabling OCPP on most stations and implementing new authentication systems for those still requiring it as of June 2026.

Affected products

  • Hydro-Québec Le Circuit Electrique charging station backend before June 2026

Timeline

  • 2026-07-07: advisory: Initial publication by CISA (ICSA-26-188-01)
  • 2026-07-10: disclosed: CVE-2026-44383 published to NVD
  • 2026-06-01: patched: Remediations implemented by Hydro-Québec in June 2026 update

References

Related threats