CVE-2026-20792
Published: 27 February 2026
Summary
CVE-2026-20792 is a high-severity Improper Restriction of Excessive Authentication Attempts (CWE-307) vulnerability in Chargemap Chargemap.Com. Its CVSS base score is 8.7 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Brute Force (T1110); ranked at the 37.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 AC-7 (Unsuccessful Logon Attempts) and SC-5 (Denial-of-service Protection).
Deeper analysis
CVE-2026-20792 is a vulnerability in the WebSocket Application Programming Interface that lacks restrictions on the number of authentication requests due to the absence of rate limiting. Published on 2026-02-27, it is associated with systems handling charger telemetry and is documented in CISA's ICS advisory ICSA-26-057-05, ChargeMap support resources, and related CSAF files. The issue corresponds to CWE-307 (Improper Restriction of Excessive Authentication Attempts) and carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Remote attackers require no privileges or user interaction and can exploit the vulnerability over the network with low attack complexity. Successful exploitation enables denial-of-service attacks by suppressing or misrouting legitimate charger telemetry data, or brute-force attacks to gain unauthorized access to the system.
Mitigation details are provided in the referenced advisories, including CISA's ICSA-26-057-05 at https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-05, the corresponding CSAF JSON file at https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-057-05.json, and ChargeMap support at https://chargemap.com/en-us/support.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-8931
Vulnerability details
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or misrouting legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized…
more
access.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Missing rate limiting on auth requests directly enables brute-force credential access (T1110) and DoS via request flooding on the service endpoint (T1499).
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
AC-7 enforces limits and lockouts on unsuccessful logon attempts, directly preventing brute-force attacks and resource exhaustion from unlimited authentication requests in the WebSocket API.
SC-5 implements denial-of-service protections like rate limiting, mitigating suppression or misrouting of legitimate charger telemetry via excessive authentication requests.
SI-4 monitors the system for indicators of excessive authentication attempts, enabling detection of brute-force or DoS exploitation in progress.