Eclipse Foundation · Eclipse Milo · CVE-2026-63248
**Name of the Vulnerable Software and Affected Versions**
Eclipse Milo versions 0.6.0 through 1.1.4
**Description**
OPC UA server diagnostics nodes fail to enforce access authorization. This allows an anonymous client to enable diagnostics via a None/None endpoint without a certificate. Additionally, a client using a trusted application certificate over SignAndEncrypt can read security diagnostics for other active sessions, which exposes usernames, login history, authentication mechanisms, security modes, policies, and public client certificates.
**Recommendations**
Update Eclipse Milo to a version later than 1.1.4.