CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
CybersecurityEV & Infrastructure

Hydro-Quebec EV charger websocket bug opens door to privilege escalation

A critical privilege escalation vulnerability affecting Hydro-Quebec’s Le Circuit Electrique EV charging station network has been disclosed, tracked as CVE-2026-20744.

CarThreat Staff
Last updated: July 18, 2026 7:24 am
By
ctadmin
2 Min Read
SHARE

A critical privilege escalation vulnerability affecting Hydro-Quebec’s Le Circuit Electrique electric vehicle charging station network has been disclosed, tracked as CVE-2026-20744.

The flaw originates in the charging station’s WebSocket endpoint, which accepts connections without requiring proper authentication. Researchers found that the backend infrastructure allows unauthenticated parties to establish communication channels that should be restricted to authorized management systems. This oversight can lead to privilege escalation, enabling unauthorized users to access sensitive backend functionalities.

The vulnerability was classified as an improper access control issue within the charging network’s infrastructure. The WebSocket protocol is used by the charging stations to communicate with the central management platform for status updates, charging session data, and remote commands. Without authentication gates on these endpoints, an attacker who identifies a station’s WebSocket address can inject commands or extract operational data.

Hydro-Quebec operates one of the largest public EV charging networks in Canada, with hundreds of stations across Quebec. The Le Circuit Electrique network supports multiple connector types and provides charging services for both casual users and commercial fleets.

The utility has implemented authentication improvements for certain charging stations that rely on the OCPP protocol. However, the advisory notes that not all stations may be fully protected depending on their specific configuration and firmware version. Hydro-Quebec recommends that operators contact the company directly to verify their charging equipment’s security posture.

Security researchers noted that EV charger backend vulnerabilities are particularly concerning because they can affect multiple stations simultaneously through a single platform weakness, rather than requiring individual physical access to each charger.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:CanadaCVE-2026-20744EV chargerHydro-QuebecLe Circuit ElectriqueOCPPPrivilege EscalationWebSocket
SOURCES:SecurityOnlineCVE Feed
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Telecom SudParis VERA tool counts 1,200 CVEs in modern car platforms

By
ctadmin
July 27, 2026
Cybersecurity

Nvidia Alpamayo 2 Super Targets L4 AV Development with Reasoning Stack

By
ctadmin
June 1, 2026
Cybersecurity

May Mobility Challenges AV Scaling Norms with Predictive World Model Architecture

By
ctadmin
May 26, 2026
Cybersecurity

New CAN dataset logs real attacks that stall Hyundai engines

By
ctadmin
August 13, 2026
Cybersecurity

Uber Invests $500M in Nuro Robotaxi Deal with Lucid Vehicles

By
ctadmin
June 12, 2026
Cybersecurity

Qualcomm critical Wi-Fi flaw reaches car cockpit chips

By
ctadmin
August 7, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?