What is CVE-2026-67870?
A security flaw in open62541 v1.5.5 involves incomplete validation of non-local ExpandedNodeId targets in the server-side AddReferences implementation. A remote attacker can send a crafted request with an empty targetServerUri and non-zero serverIndex, leading to a target node pointer issue. Users are advised to update to the latest version.
Azərbaycanca: open62541 v1.5.5 server tərəfində AddReferences əməliyyatı qeyri-local ExpandedNodeId hədəflərinin yoxlanmasında natamam təhlükəsizlik qüsuru aşkarlanıb. Uzaqdan hücum edən şəxs xüsusi hazırlanmış sorğu göndərərək hədəf node pointer probleminə səbəb ola bilər. İstifadəçilərə kitabxananı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which version of open62541 is affected by CVE-2026-67870?
CVE-2026-67870 specifically affects version v1.5.5 of the open62541 library.
What can a remote attacker achieve by exploiting CVE-2026-67870?
A remote attacker can cause a target node pointer issue by sending a crafted request with an empty targetServerUri and non-zero serverIndex.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.