๐Ÿ” CVE Alert

CVE-2026-63248

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.

CWE CWE-862
Vendor eclipse foundation
Product eclipse milo
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse milo

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse milo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Milo
0.6.0 โ‰ค 1.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/eclipse-milo/milo/commit/a5dae1be0657d2b4fcb66e63f377c1dc36069e2a gitlab.eclipse.org: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/181

Credits

Abhinav Agarwal (GitHub: @abhinavagarwal07)