CVE-2026-27647 Details
Description
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
A vulnerability in the WebSocket backend of Mobility46's EV charging management system allows multiple endpoints to connect using the same session identifier. This flaw creates predictable session identifiers, enabling session hijacking or shadowing. The most recent connection can displace the legitimate charging station, receiving backend commands intended for that station. This vulnerability could allow unauthorized users to authenticate as other users or enable a denial-of-service condition by overwhelming the backend with valid session requests.
Mobility46 did not respond to CISA's request for coordination. Contact Mobility46 using their contact page for more information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-057-08.json | [email protected] | Third Party Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-08 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.mobility46.se/en/contact-us | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mobility46 mobility46.se | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 5, 2026 | CVE Modified | [email protected] |
| Mar 2, 2026 | Initial Analysis | [email protected] |
| Feb 27, 2026 | New CVE Received | [email protected] |