CVE-2026-31926 Details
Description
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
A vulnerability exists in Automated Logic WebCTRL Premium Server that allows charging station authentication identifiers to be accessed publicly through web-based mapping platforms. This issue arises from cleartext transmission of sensitive information, which can be intercepted and modified by an attacker. The vulnerability affects WebCTRL Premium Server versions 8.5 cumulative releases and later.
For customers using supported versions of WebCTRL (WebCTRL 8.5 cumulative releases and later), Automated Logic provides secure configuration guidance for hardware and software deployments, BACnet Secure Connect (BACnet/SC) support which introduces TLS encryption and mutual authentication, and published best practices for network segmentation, access control, and secure protocol implementation. Additional information is available on the Automated Logic website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | CISA-ADP |
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 23, 2026 | CVE Modified | CISA-ADP |
| Mar 20, 2026 | New CVE Received | [email protected] |