Description
node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not verify that the trailing bytes match the current session serverNonce. An unauthenticated remote attacker can obtain the server public key through GetEndpoints and forge a blob whose little-endian length produces an empty password passed to isValidUser, compromising accounts that accept an empty password. Missing nonce binding also allows a captured UserNameIdentityToken ciphertext to be replayed in another session, and SecurityMode=None removes the separate client-signature safeguard. This issue is fixed in version 2.166.0.
Published: 2026-09-14
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access via empty password impersonation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in node‑opcua’s UserNameIdentityToken authentication logic, which decrypts an RSA‑OAEP encoded password blob without verifying that the appended bytes match the current session’s serverNonce. An unauthenticated remote attacker can retrieve the server’s public key by calling GetEndpoints, craft a ciphertext whose little‑endian length resolves to an empty password, and have the server accept it during isValidUser, enabling compromise of any account that permits an empty password. The missing nonce binding also permits the forged token to be replayed in other sessions, and with SecurityMode set to None the additional client‑signature protection is absent, further easing the attack. The flaw is fixed in node‑opcua v2.166.0.

Affected Systems

Node-opcua v2.x for Node.js and TypeScript applications that use the UserNameIdentityToken authentication flow, particularly versions prior to 2.166.0. The vulnerability impacts any installation that accepts empty passwords and relies on node‑opcua’s server implementation located in packages/node‑opcua-server/source/opcua_server.ts.

Risk and Exploitability

The vulnerability scores a CVSS of 7.7, indicating a high risk of unauthorized access. The EPSS score is below 1%, and it is not listed in CISA’s KEV catalog, suggesting a low but non‑zero exploitation probability. Remote attackers can exploit the weakness by first querying GetEndpoints to obtain the server’s public key, then sending a specially crafted RSA‑OAEP blob that tricks the server into accepting an empty password. Because the nonce is not bound to the session, malicious tokens can be replayed across sessions, and the absence of client signatures when SecurityMode=None removes an important safeguard. Given the potential for account takeover and the ease of exploitation, remediation should be treated as urgent.

Generated by OpenCVE AI on September 21, 2026 at 00:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade node‑opcua to v2.166.0 or later to apply the nonce verification fix
  • Configure the server to use a SecurityMode of SignAndEncrypt or at least Sign to ensure client signatures protect the authentication flow
  • Enforce a strict password policy that disallows empty passwords or disable UserNameIdentityToken authentication where possible

Generated by OpenCVE AI on September 21, 2026 at 00:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mq36-523m-x7vv node-opcua missing nonce verification in UserNameIdentityToken authentication
History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Node-opcua Project
Node-opcua Project node-opcua
Vendors & Products Node-opcua Project
Node-opcua Project node-opcua

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not verify that the trailing bytes match the current session serverNonce. An unauthenticated remote attacker can obtain the server public key through GetEndpoints and forge a blob whose little-endian length produces an empty password passed to isValidUser, compromising accounts that accept an empty password. Missing nonce binding also allows a captured UserNameIdentityToken ciphertext to be replayed in another session, and SecurityMode=None removes the separate client-signature safeguard. This issue is fixed in version 2.166.0.
Title node-opcua: Missing nonce verification in UserNameIdentityToken authentication
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Node-opcua Project Node-opcua
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:39:35.824Z

Reserved: 2026-06-11T21:15:33.872Z

Link: CVE-2026-54155

cve-icon Vulnrichment

Updated: 2026-09-14T16:39:26.917Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T17:17:46.737

Modified: 2026-09-30T19:38:27.293

Link: CVE-2026-54155

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature