Improper Signature Verification in Apache PLC4X OPC UA Driver
CVE-2026-102508
What is CVE-2026-102508?
The OPC UA driver in Apache PLC4X is susceptible to an improper verification of cryptographic signatures and flawed certificate validation. This vulnerability allows attackers in a network position between a client and server to impersonate the OPC UA server. As a result, they may read, forge, or modify secure-channel traffic, which can include sensitive user credentials sent by clients. The risk varies by version: older versions fail to enforce message-signature checks and use unauthenticated certificates, while transitional versions mismanage signature validation and server certificates. All affected versions default to an insecure security policy, making it easy for users to misjudge their vulnerability status. Upgrading to version 1.0.0 is crucial, as it rectifies these issues by ensuring proper signature verification and establishing secure connections.
Affected Version(s)
Apache PLC4X 0.9.0 < 1.0.0
Apache PLC4X 1.0.0