Critical Improper Access Control in Hydro‑Québec Le Circuit Electrique Charging‑Station Backend (CVE‑2026‑20744) Threatens Infrastructure
What It Is — The charging‑station backend accepts WebSocket connections without proper authentication, enabling privilege escalation and potential denial‑of‑service. The flaw also allows unlimited authentication attempts and lacks session expiration.
Exploitability — CVSS v3 9.8 (Critical). Publicly disclosed; active exploitation is possible. No public proof‑of‑concept is required beyond a simple unauthenticated WebSocket request.
Affected Products — Hydro‑Québec Le Circuit Electrique charging‑station backend (versions < June 2026).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Security principle demands enforceable logical access controls; this vulnerability shows a gap in authentication and session management.
- Continuous monitoring of failed login attempts and session lifecycles provides audit‑ready evidence of control effectiveness.
- Enterprise buyers of critical‑infrastructure services now require demonstrable SOC 2 compliance; unaddressed access‑control flaws can block contracts.
Recommended Actions
- Deploy Hydro‑Québec’s remediation: disable OCPP where possible and enable strong authentication on all affected stations.
- Map the issue to SOC 2 CC6.1 (Logical Access) and CC6.2 (System Operations); update access‑control policies, enforce session timeouts, and log authentication events.
- Capture remediation evidence (patch logs, configuration snapshots) in a continuous‑compliance repository for audit readiness.
Source: CISA Advisory – ICS‑A‑26‑188‑01