Access Control Vulnerability in Eclipse Milo OPC UA Server
CVE-2026-63248

6.9MEDIUM

Key Information:

Vendor
CVE Published:
4 August 2026

What is CVE-2026-63248?

In specific versions of Eclipse Milo, the OPC UA server does not enforce proper access authorization for diagnostics nodes. This flaw allows an anonymous client to enable diagnostics without the need for a certificate over a None/None endpoint. Furthermore, if a trusted client application certificate is utilized over SignAndEncrypt, it can access sensitive security diagnostics for other active sessions. This exposure could reveal critical details such as usernames, login history, authentication methods, security modes and policies, and public client certificates, potentially compromising user security.

Affected Version(s)

Eclipse Milo 0.6.0 <= 1.1.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abhinav Agarwal (GitHub: @abhinavagarwal07)
.