Description
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.
Published: 2026-08-04
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises because Eclipse Milo OPC UA servers fail to enforce authorization on diagnostics nodes, allowing clients to enable diagnostics on a None/None endpoint without a certificate. When a trusted client presents a valid certificate under SignAndEncrypt, it can read detailed security diagnostics from other active sessions, which reveals usernames, login history, authentication mechanisms, security modes and policies, and public client certificates. This results in the disclosure of sensitive operational information to unauthorized parties.

Affected Systems

The affected products are Eclipse Foundation products under the Eclipse Milo project, specifically server implementations in versions ranging from 0.6.0 up to and including 1.1.4. No further vendor subcomponents are listed.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity flaw, and an EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via an OPC UA endpoint that allows anonymous connection or a trusted client certificate. The scenario requires the attacker to access an OPC UA server exposed over the network and to have either an ability to connect anonymously or a valid application certificate; once connected, the attacker can query diagnostics nodes and retrieve confidential session information. Implications include compromised confidentiality of user credentials and system audit data.

Generated by OpenCVE AI on August 4, 2026 at 19:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Eclipse Milo to the latest release or apply the vendor’s patch that restores proper authorization checks on diagnostics nodes.
  • Configure the OPC UA server to disable or restrict diagnostics nodes, ensuring they are inaccessible to anonymous or unauthorized clients.
  • Enforce strict authentication policies for diagnostics endpoints and review access controls to prevent privileged data exposure.

Generated by OpenCVE AI on August 4, 2026 at 19:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Missing Authorization on OPC UA Server Diagnostics in Eclipse Milo

Tue, 04 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse milo
Vendors & Products Eclipse
Eclipse milo

Tue, 04 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-08-04T15:02:13.054Z

Reserved: 2026-07-16T13:58:02.238Z

Link: CVE-2026-63248

cve-icon Vulnrichment

Updated: 2026-08-04T14:28:15.989Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T13:18:55.790

Modified: 2026-08-05T18:55:55.773

Link: CVE-2026-63248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:00:05Z

Weaknesses