CVE-2026-6899 Details
Description
Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.
A vulnerability exists in the S2OPC library's CycloneCrypto cryptographic wrapper, where the certificate revocation check only considers the first matching Certificate Revocation List (CRL) and ignores other valid CRLs from the same Certificate Authority (CA). This flaw could allow an OPC UA client to maintain a connection with a server while using a revoked certificate.
The issue has been fixed in the S2OPC library by updating the certificate revocation check to consider all valid CRLs associated with the same CA. Instructions for applying this fix can be found in the S2OPC GitLab repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 9, 2026CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.com/systerel/S2OPC/-/work_items/1739 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-299 | Improper Check for Certificate Revocation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Systerel S2OPC | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | New CVE Received | [email protected] |
Volerion