Improper Signature Verification in Apache PLC4X OPC UA Driver
CVE-2026-102508

9.2CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102508?

The OPC UA driver in Apache PLC4X is susceptible to an improper verification of cryptographic signatures and flawed certificate validation. This vulnerability allows attackers in a network position between a client and server to impersonate the OPC UA server. As a result, they may read, forge, or modify secure-channel traffic, which can include sensitive user credentials sent by clients. The risk varies by version: older versions fail to enforce message-signature checks and use unauthenticated certificates, while transitional versions mismanage signature validation and server certificates. All affected versions default to an insecure security policy, making it easy for users to misjudge their vulnerability status. Upgrading to version 1.0.0 is crucial, as it rectifies these issues by ensuring proper signature verification and establishing secure connections.

Affected Version(s)

Apache PLC4X 0.9.0 < 1.0.0

Apache PLC4X 1.0.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abhinav Agarwal
.