


Perceptive Security
SOC/SIEM Consultancy

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component
Published:
4 August 2026 at 00:00:00
Alert date:
5 August 2026 at 01:03:20
Source:
nvd.nist.gov
Critical Infrastructure, Mobile & IoT, Network Infrastructure
CVE-2026-67861 is a vulnerability affecting open62541 version 1.5.5 and earlier, an open-source OPC UA implementation. A remote attacker can exploit the UA_Client_getRemoteDataTypes component to cause a denial of service condition. The vulnerability is remotely exploitable without requiring authentication. The issue has been documented on the open62541 GitHub repository. Affected code paths include the client utility functions in ua_client_util.c and related custom datatype handling examples. Given the industrial and IoT context of OPC UA, this vulnerability may affect critical infrastructure environments. Users are advised to review the referenced GitHub issue and update to a patched version when available.
Technical details
Mitigation steps:
Affected products:
open62541 v1.5.5 and before
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67861
https://github.com/open62541/open62541/issues/8140
https://raw.githubusercontent.com/open62541/open62541/v1.5.5/examples/custom_datatype/client_types_custom.c
https://raw.githubusercontent.com/open62541/open62541/v1.5.5/src/client/ua_client_util.c
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
