Loading market data...
← Back to CVE feed

CVE-2026-63248

UNKNOWN View on NVD ↗

Description

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.

Published: Aug 04, 2026 13:18 UTC Modified: Aug 04, 2026 16:16 UTC