CVE-2026-62927 Details
Description
In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.
An authorization bypass vulnerability has been identified in the Eclipse Milo OPC UA SDK, specifically in versions 1.0.0 through 1.1.4. The issue arises within the Call service's method dispatch process. When an anonymous or low-privileged client sends a mixed batch of method calls, the service incorrectly processes denied methods by allowing them to execute if they are bundled with permitted ones. This flaw enables unauthorized access to restricted methods, undermining the application's authorization controls.
Users can update to Eclipse Milo version 1.1.6 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/eclipse-milo/milo/commit/59b50bed094de0d18a130a48f3527254dc76105d | [email protected] | Patch |
| https://gitlab.eclipse.org/security/cve-assignment/-/work_items/178 | [email protected] | Issue TrackingPatchVendor Advisory |
| https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| eclipse milo | >= 1.0.0, < 1.1.5 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | Initial Analysis | [email protected] |
| Aug 4, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | New CVE Received | [email protected] |