PT-2026-67699 · Eclipse Foundation · Eclipse Milo

·

CVE-2026-63248

·

Published

2026-08-04

·

Updated

2026-08-05

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Eclipse Milo versions 0.6.0 through 1.1.4
Description OPC UA server diagnostics nodes fail to enforce access authorization. This allows an anonymous client to enable diagnostics via a None/None endpoint without a certificate. Additionally, a client using a trusted application certificate over SignAndEncrypt can read security diagnostics for other active sessions, which exposes usernames, login history, authentication mechanisms, security modes, policies, and public client certificates.
Recommendations Update Eclipse Milo to a version later than 1.1.4.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63248

Affected Products

Eclipse Milo