CVE-2026-63248
Received Received - Intake

Unauthorized Access to OPC UA Diagnostics in Eclipse Milo

Vulnerability report for CVE-2026-63248, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: Eclipse Foundation

Description

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
eclipse milo From 0.6.0 (inc) to 1.1.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Eclipse Milo OPC UA server versions 0.6.0 to 1.1.4. It allows anonymous clients to enable diagnostics without authentication over insecure endpoints. With a trusted certificate using SignAndEncrypt, attackers can read security diagnostics for other sessions, exposing usernames, login history, authentication details, security modes, and public certificates.

Detection Guidance

Check if Eclipse Milo versions 0.6.0 through 1.1.4 are installed. Inspect OPC UA server configurations for None/None endpoints without certificate requirements. Monitor for unauthorized access to diagnostics nodes or unusual reads of security diagnostics data.

Impact Analysis

Attackers could gain unauthorized access to sensitive session data, including user credentials and authentication methods. This could lead to further attacks like session hijacking or privilege escalation. Systems relying on Eclipse Milo for OPC UA communication are at risk of information disclosure.

Compliance Impact

This vulnerability could violate GDPR and HIPAA by exposing personal and sensitive data without authorization. GDPR requires protecting personal data, while HIPAA mandates safeguarding health information. Unauthorized access risks non-compliance and potential legal penalties.

Mitigation Strategies

Upgrade Eclipse Milo to a version beyond 1.1.4. Disable None/None endpoints and enforce certificate-based authentication. Restrict access to diagnostics nodes using role-based permissions. Set SessionSecurityDiagnosticsAccessMode to RESTRICTED in configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63248. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart