


Perceptive Security
SOC/SIEM Consultancy

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against r…
Published:
6 August 2026 at 00:00:00
Alert date:
6 August 2026 at 03:01:36
Source:
nvd.nist.gov
Critical Infrastructure, Network Infrastructure
A buffer overflow vulnerability (CVE-2026-67869) has been identified in open62541 version 1.5.5, an open-source OPC UA implementation. The vulnerability exists in the Service_Call function, which validates input arguments against runtime-resolved InputArguments metadata. A remote attacker can exploit this flaw to cause a denial of service condition. The vulnerability is rooted in improper input validation within the server's method service handling and alarm/condition subscription components. Affected source files include ua_services_method.c and ua_subscription_alarms_conditions.c. The issue has been documented in the project's GitHub issue tracker. No authentication details are specified, suggesting the attack surface may be accessible to unauthenticated remote attackers. The criticality is rated High due to the potential for remote denial of service against OPC UA industrial servers.
Technical details
Mitigation steps:
Affected products:
open62541 v1.5.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67869
https://github.com/open62541/open62541/blob/v1.5.5/examples/tutorial_server_alarms_conditions.c
https://github.com/open62541/open62541/blob/v1.5.5/src/server/ua_services_method.c
https://github.com/open62541/open62541/blob/v1.5.5/src/server/ua_subscription_alarms_conditions.c
https://github.com/open62541/open62541/issues/8171
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
