---
id: CVE-2026-44383
title: |-
  Multiple connections to the backend using the same charging station ID 
  are allowed, which could allow an attacker to deploy multiple instances 
  of malicious OCPP clients to overwhelm the backend.
summary: |-
  Multiple connections to the backend using the same charging station ID 
  are allowed, which could allow an attacker to deploy multiple instances 
  of malicious OCPP clients to overwhelm the backend.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-613
published: '2026-07-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44383'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.hydroquebec.com/nous-joindre/'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00563
epssPercentile: 0.44486
ingestedAt: '2026-07-11T22:16:01.012Z'
---

## Overview

Multiple connections to the backend using the same charging station ID 
are allowed, which could allow an attacker to deploy multiple instances 
of malicious OCPP clients to overwhelm the backend.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
