In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.
References
| Link | Resource |
|---|---|
| https://github.com/eclipse-milo/milo/commit/a5dae1be0657d2b4fcb66e63f377c1dc36069e2a | Patch |
| https://gitlab.eclipse.org/security/cve-assignment/-/work_items/181 | Issue Tracking Patch Vendor Advisory |
| https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 | Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-04 13:18
Updated : 2026-08-05 18:55
NVD link : CVE-2026-63248
Mitre link : CVE-2026-63248
CVE.ORG link : CVE-2026-63248
JSON object : View
Products Affected
eclipse
- milo
CWE
CWE-862
Missing Authorization
