CVE-2026-6899
Last modified
CVE-2026-6899 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-6899?
How severe is CVE-2026-6899?
How do I fix CVE-2026-6899?
Are you affected by CVE-2026-6899?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
