CVE-2026-67870

Description

A flaw was found in open62541. A remote attacker can exploit an incomplete validation flaw in the server-side AddReferences implementation. By sending a specially crafted request, an attacker can cause a null pointer dereference, leading to a Denial of Service (DoS) condition. This can make the server unavailable to legitimate users.

Statement

This Important denial of service flaw in open62541 allows a remote, unauthenticated attacker to crash the server. The vulnerability arises from insufficient validation of non-local ExpandedNodeId targets within the AddReferences implementation, which can lead to a NULL pointer dereference and service unavailability.

Mitigation

Restrict who can invoke NodeManagement / AddReferences (trusted clients only)
and limit OPC UA server network exposure.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Crash, Exit, or Restart

NULL pointer dereferences usually result in the failure of the process unless exception handling (on some platforms) is available and implemented. Even when exception handling is being used, it can still be very difficult to return the software to a safe state of operation.

Integrity,Confidentiality

Technical Impact: Execute Unauthorized Code or Commands; Read Memory; Modify Memory

In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution.

Frequently Asked Questions

Want to get errata notifications? Sign up here.