CVE-2026-58080
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted to read role-permission metadata, invoke protected methods, or delete protected nodes.
| CWE | CWE-862 |
| Vendor | eclipse foundation |
| Product | eclipse milo |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation eclipse milo
Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse milo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Eclipse Foundation / Eclipse Milo
1.0.0 < 1.1.5
References
Credits
Abhinav Agarwal (GitHub: @abhinavagarwal07)