CVE-2026-63248 Details
Description
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.
A vulnerability exists in Eclipse Milo OPC UA server in versions 0.6.0 through 1.1.4, where security diagnostics nodes do not properly enforce access authorization. This flaw allows an anonymous client to enable diagnostics on a None/None endpoint without a certificate. Furthermore, with a trusted client application certificate over SignAndEncrypt, the client can access security diagnostics of other active sessions. This exposure includes usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.
Users can update to Eclipse Milo version 1.1.6, where this vulnerability has been addressed. Instructions for updating can be found in the Eclipse Milo repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/eclipse-milo/milo/commit/a5dae1be0657d2b4fcb66e63f377c1dc36069e2a | [email protected] | Patch |
| https://gitlab.eclipse.org/security/cve-assignment/-/work_items/181 | [email protected] | Issue TrackingPatchVendor Advisory |
| https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| eclipse milo | >= 0.6.0, < 1.1.5 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | Initial Analysis | [email protected] |
| Aug 4, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | New CVE Received | [email protected] |