CVE-2026-29044 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the TransactionStarted event, AuthHandler d…
Medium CVSS: 5.0

CVE-2026-29044

EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the TransactionStarted event, AuthHandler determines `transaction_active=false` and only calls `withdraw_authorization_callback`. This path ultimately calls `Charger::deauthorize()`, but no actual stop (StopTransaction) occurs in the Charging state. As a result, authorization withdrawal can be defeated by timing, allowing charging to continue. Version 2026.02.0 contains a patch.
Vendor
Linuxfoundation
Product
Everest
CWE
CWE-863
Yayın Tarihi
2026-03-26 17:16:34
Güncelleme
2026-03-31 14:40:50
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar