PT-2026-67699 · Eclipse Foundation · Eclipse Milo
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Milo versions 0.6.0 through 1.1.4
Description
OPC UA server diagnostics nodes fail to enforce access authorization. This allows an anonymous client to enable diagnostics via a None/None endpoint without a certificate. Additionally, a client using a trusted application certificate over SignAndEncrypt can read security diagnostics for other active sessions, which exposes usernames, login history, authentication mechanisms, security modes, policies, and public client certificates.
Recommendations
Update Eclipse Milo to a version later than 1.1.4.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse Milo