CVE-2026-6899
Received
Received - Intake
Certificate Revocation Bypass in S2OPC CycloneCrypto
Publication date: 2026-06-09
Last updated on: 2026-06-09
Assigner: GitLab Inc.
Description
Description
Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| systerel | s2opc | * |
| cyclonecrypto | cyclone | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-299 | The product does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised. |