CVE-2026-67869 Details
Description
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
A buffer overflow vulnerability has been identified in open62541 version 1.5.5. This vulnerability allows a remote attacker to cause a denial-of-service by exploiting a type confusion in the built-in Alarms and Conditions Acknowledge method. The issue arises because the method input validation can be manipulated to bypass standard argument checks, leading to an out-of-bounds read and a heap-buffer-overflow. This exploitation is possible through legitimate OPC UA service operations, causing the server to crash.
Users can update to the latest version of open62541, where this vulnerability has been addressed. Instructions for updating can be found in the open62541 GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/open62541/open62541/issues/8171 | CISA-ADP | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/open62541/open62541/blob/v1.5.5/examples/tutorial_server_alarms_conditions.c | [email protected] | Source CodeVendor |
| https://github.com/open62541/open62541/blob/v1.5.5/src/server/ua_services_method.c | [email protected] | Source CodeVendor |
| https://github.com/open62541/open62541/blob/v1.5.5/src/server/ua_subscription_alarms_conditions.c | [email protected] | Source CodeVendor |
| https://github.com/open62541/open62541/issues/8171 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| open62541 | 1.5.5 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion