๐Ÿ” CVE Alert

CVE-2026-58080

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted to read role-permission metadata, invoke protected methods, or delete protected nodes.

CWE CWE-862
Vendor eclipse foundation
Product eclipse milo
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse milo

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse milo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Milo
1.0.0 < 1.1.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/eclipse-milo/milo/commit/d51f03e9a75f313ab41c3d68d809f4b922073f1a gitlab.eclipse.org: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/180

Credits

Abhinav Agarwal (GitHub: @abhinavagarwal07)