{"id":"CVE-2026-58080","published":"2026-08-04T13:18:55.293","lastModified":"2026-08-05T20:27:11.010","description":"In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted to read role-permission metadata, invoke protected methods, or delete protected nodes.","cvssScore":8.2,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","cwes":["CWE-862"],"vendors":["eclipse"],"products":["milo"],"references":[{"url":"https://github.com/eclipse-milo/milo/commit/d51f03e9a75f313ab41c3d68d809f4b922073f1a","tags":["Patch"]},{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/180","tags":["Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598","tags":["Issue Tracking","Vendor Advisory"]}],"exploitRefs":[{"url":"https://github.com/eclipse-milo/milo/commit/d51f03e9a75f313ab41c3d68d809f4b922073f1a","tags":["Patch"]}],"hasPoc":true,"ai":{"summary":"The flaw allows an anonymous client to bypass role-permission checks by exploiting a configuration issue in Eclipse Milo versions 1.0.0 through 1.1.4, leading to unauthorized access.","exploitability":"Exploitation requires the server to use `copy()` for configuration and allow anonymous sessions with permission to read or modify protected data.","blast_radius":"If exploited, this could lead to significant data breaches or unauthorized control of critical systems relying on role-based permissions.","remediation":"Update to Eclipse Milo version 1.1.5 or later which addresses the issue.","tags":["auth-bypass","ics","config-flaw"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:49:05.344Z"}}