Vulnerability Description
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Milo | >= 0.6.0, < 1.1.5 |
Related Weaknesses (CWE)
References
- https://github.com/eclipse-milo/milo/commit/a5dae1be0657d2b4fcb66e63f377c1dc3606Patch
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/181Issue TrackingPatchVendor Advisory
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598Issue TrackingVendor Advisory
FAQ
What is CVE-2026-63248?
CVE-2026-63248 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certif...
How severe is CVE-2026-63248?
CVE-2026-63248 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-63248?
Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Milo.