What is CVE-2026-58080?
In Eclipse Milo versions 1.0.0 through 1.1.4, the `OpcUaServerConfig.copy()` method fails to preserve a configured `RoleMapper`, causing sessions to receive no role IDs and bypassing role-permission checks. Affected servers relying on role-based access control must upgrade the library or avoid using `copy()` for runtime configuration.
Azərbaycanca: Eclipse Milo kitabxanasında `OpcUaServerConfig.copy()` metodu `RoleMapper` konfiqurasiyasını itirir, bu da rol əsaslı icazə yoxlamalarını sıradan çıxarır. Təsirə məruz qalan serverlərdə (1.0.0-1.1.4) sessiyalara heç bir rol təyin olunmur. Dərhal kitabxana yenilənməli və ya `copy()` istifadəsindən qaçınmalısınız.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
How does CVE-2026-58080 in the Eclipse Milo library bypass role-based access control?
The `OpcUaServerConfig.copy()` method fails to preserve the `RoleMapper` configuration, so sessions receive no role IDs, causing role-permission checks to be completely bypassed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.