Incomplete Validation Flaw in open62541 Server-Side Implementation
CVE-2026-67870
9.8CRITICAL
What is CVE-2026-67870?
The open62541 library version 1.5.5 has a server-side vulnerability in its AddReferences implementation that allows a remote attacker to exploit incomplete validation of non-local ExpandedNodeId targets. An attacker could send a specially crafted AddReferencesRequest with both an empty targetServerUri and a non-zero targetNodeId.serverIndex. This can lead to the target node pointer remaining NULL, resulting in unexpected behavior during execution and potentially allowing further exploitation of server-side functions.
