In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.
References
| Link | Resource |
|---|---|
| https://github.com/eclipse-milo/milo/commit/a5dae1be0657d2b4fcb66e63f377c1dc36069e2a | Patch |
| https://gitlab.eclipse.org/security/cve-assignment/-/work_items/181 | Issue Tracking Patch Vendor Advisory |
| https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 | Issue Tracking Vendor Advisory |
Configurations
History
05 Aug 2026, 18:55
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Eclipse milo
Eclipse |
|
| References | () https://github.com/eclipse-milo/milo/commit/a5dae1be0657d2b4fcb66e63f377c1dc36069e2a - Patch | |
| References | () https://gitlab.eclipse.org/security/cve-assignment/-/work_items/181 - Issue Tracking, Patch, Vendor Advisory | |
| References | () https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 - Issue Tracking, Vendor Advisory | |
| CPE | cpe:2.3:a:eclipse:milo:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
04 Aug 2026, 13:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-04 13:18
Updated : 2026-08-05 18:55
NVD link : CVE-2026-63248
Mitre link : CVE-2026-63248
CVE.ORG link : CVE-2026-63248
JSON object : View
Products Affected
eclipse
- milo
CWE
CWE-862
Missing Authorization
