CVE-2026-63248
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.
| CWE | CWE-862 |
| Vendor | eclipse foundation |
| Product | eclipse milo |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation eclipse milo
Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse milo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Eclipse Foundation / Eclipse Milo
0.6.0 โค 1.1.4
References
Credits
Abhinav Agarwal (GitHub: @abhinavagarwal07)