Certificate Revocation Issue in S2OPC Library Affecting CycloneCrypto
CVE-2026-6899
5.6MEDIUM
What is CVE-2026-6899?
The S2OPC library's CycloneCrypto component has a vulnerability that compromises certificate revocation checks. It only checks the first matching Certificate Revocation List (CRL), neglecting additional valid CRLs issued by the same Certificate Authority (CA). This flaw may enable an OPC UA client and server to establish a connection using certificates that have been revoked, potentially exposing systems to security risks.
Affected Version(s)
S2OPC 1.5.0 < 1.7.3
