PT-2026-28383 · Everest · Everest

Finder16

·

Published

2026-03-26

·

Updated

2026-03-27

·

CVE-2026-29044

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions EVerest versions prior to 2026.02.0
Description EVerest is an EV charging software stack. When WithdrawAuthorization is processed before the TransactionStarted event, AuthHandler determines transaction active=false and only calls withdraw authorization callback. This path ultimately calls Charger::deauthorize(), but no actual StopTransaction occurs in the Charging state. As a result, authorization withdrawal can be defeated by timing, allowing charging to continue. The vulnerable code path involves the withdraw authorization callback function and the Charger::deauthorize() function. The transaction active variable is a key component in determining the correct authorization flow.
Recommendations Update to version 2026.02.0 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-29044
GHSA-GX37-P775-QF5V

Affected Products

Everest