
Hydro-Québec Le Circuit Electrique charging station backend
Recent vulnerabilities have been identified in the Hydro-Québec Le Circuit Electrique charging station backend, with a CVSS score of 9.8 indicating critical severity. These flaws, including improper access control and insufficient session expiration, could allow for privilege escalation and potential denial-of-service attacks. The affected products are deployed in Canada, highlighting concerns for critical transportation systems. The main vulnerability, CVE-2026-20744, allows unauthenticated connections to the websocket endpoint.










