AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-63248

MEDIUM · CVSS 6.5 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Eclipse Milo versions 0.6.0 through 1.1.4 have a vulnerability where OPC UA server diagnostics nodes lack proper access authorization, allowing unauthorized anonymous clients to access sensitive diagnostics information. This exposure can lead to the disclosure of usernames, login history, and other security-related details, potentially compromising the integrity of the system. Organizations utilizing affected versions of Eclipse Milo should prioritize addressing this vulnerability to safeguard their OPC UA implementations.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63248
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%

Original NVD Description

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.

Related CVEs

Other vulnerabilities affecting the same vendor(s)