CVE-2026-67864
Received Received - Intake

Denial of Service in open62541 OPC UA Stack

Vulnerability report for CVE-2026-67864, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-06

Assigner: MITRE

Description

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-06
Generated
2026-08-16
AI Q&A
2026-08-06
EPSS Evaluated
2026-08-15
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open62541 open62541 to 1.5.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service issue in the open62541 library versions 1.5.5 and earlier. It is caused by a flaw in the NodeManagement type-instantiation logic component, which could allow a remote attacker to disrupt service.

Detection Guidance

To detect this vulnerability, monitor for crashes in open62541 OPC UA servers, particularly during NodeManagement operations. Check server logs for stack overflow errors or process terminations. Test with malicious clients sending self-referential ObjectType requests to trigger infinite recursion. Use the official ci_server.c example to reproduce the issue over a network connection.

Impact Analysis

If exploited, this vulnerability could cause your open62541-based system to become unavailable or unresponsive, leading to service disruptions for applications relying on this library.

Compliance Impact

The provided CVE data does not specify any impact on compliance with standards like GDPR or HIPAA. The vulnerability only describes a denial-of-service issue in open62541 without details on data exposure or regulatory implications.

Mitigation Strategies

Upgrade open62541 to a version newer than v1.5.5 to address the NodeManagement type-instantiation logic flaw that enables denial of service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67864. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart