Impact
In Eclipse Milo versions 1.0.0 through 1.1.4, the OpcUaServerConfig.copy method fails to preserve a configured RoleMapper, causing session objects to lack role identifiers and allowing the default access controller to skip role‑permission checks. Consequently, any client that can establish an anonymous session can read role‑permission metadata, invoke protected methods, or delete protected nodes. This flaw is a CWE‑862 authorization bypass that can provide an attacker with elevated privileges on the server.
Affected Systems
The affected product is Eclipse Foundation’s Eclipse Milo. Versions 1.0.0 up to and including 1.1.4 are impacted. No other Eclipse Milo releases or versions are known to be vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity for this flaw, while the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely exploit the flaw remotely by creating an anonymous session against a Milo server that has anonymous access enabled and relies on the copy method to construct its runtime configuration. Because the flaw results in the bypass of role‑based checks, an attacker gains unauthorized read, write, or delete capabilities wherever those permissions are protected.
OpenCVE Enrichment