Incomplete Validation Flaw in open62541 Server-Side Implementation
CVE-2026-67870

9.8CRITICAL

Key Information:

Vendor

open62541

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-67870?

The open62541 library version 1.5.5 has a server-side vulnerability in its AddReferences implementation that allows a remote attacker to exploit incomplete validation of non-local ExpandedNodeId targets. An attacker could send a specially crafted AddReferencesRequest with both an empty targetServerUri and a non-zero targetNodeId.serverIndex. This can lead to the target node pointer remaining NULL, resulting in unexpected behavior during execution and potentially allowing further exploitation of server-side functions.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.