Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102508— Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade

Quick assessment

Affected
Apache Software Foundation Apache PLC4X
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache PLC4X(PLC4J)中的 OPC UA 驱动存在加密签名验证不当和证书验证不当的漏洞,使得处于客户端与服务器之间网络位置的攻击者能够冒充 OPC UA 服务器,并读取、伪造或修改安全通道中的流量(包括客户端发送的用户凭据)。 该缺陷在不同版本中表现不同: 在 0.9.0 至 0.11.0 版本中,消息签名校验失败仅被记录日志,从未强制执行;且不存在验证服务器证书的机制:证书直接取自未经身份验证的 GetEndpoints 发现响应,并用于加密用户密码。 在 0.12.0 至 0.13.1 版本中,

CVSS 9.2 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102508

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client. The defect manifests differently depending on the version: - In 0.9.0 through 0.11.0 a failed message-signature check is only logged and never enforced, and there is no mechanism to verify the server certificate: it is taken from the unauthenticated GetEndpoints discovery response and used to encrypt the user's password. - In 0.12.0 through 0.13.1 the signature check is inverted (valid signatures are rejected, invalid ones accepted), and server certificates are accepted without a trust anchor by default. - In all affected versions the default security policy is None. Starting with 0.12.0 the driver additionally continues silently at a weaker security policy than the one configured, and starting with 0.13.0 endpoint selection prefers the weakest matching endpoint. Users checking only for one of these mechanisms may wrongly conclude they are unaffected. This issue affects Apache PLC4X: from 0.9.0 before 1.0.0. Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 verifies message signatures correctly, refuses to connect unless the server certificate can be verified against a configured trust store or pinned certificate, defaults to Basic256Sha256 with SignAndEncrypt, and fails the connection if the negotiated security policy is weaker than the configured one.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache PLC4X 0.9.0 ~ 1.0.0 -

II. Public POCs for CVE-2026-102508

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102508

请登录查看更多情报信息。

Mailing List Discussions for CVE-2026-102508 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-30 · 19 CVEs total

CVE-2026-94052 9.1 CRITICAL Apache MINA SSHD: LDAP password authentication ineffective
CVE-2026-94053 9.1 CRITICAL Apache MINA SSHD: LDAP injection in sshd-ldap
CVE-2026-77185 9.1 CRITICAL Apache MINA SSHD: Asynchronous authentication can bypass signature verification
CVE-2026-102509 8.7 HIGH Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver an
CVE-2026-102510 8.7 HIGH Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled len
CVE-2026-102511 8.5 HIGH Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed resp
CVE-2026-93994 8.1 HIGH Apache MINA SSHD: Repeated-publickey policy bypass on server
CVE-2026-94002 7.5 HIGH Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies
CVE-2026-93995 6.5 MEDIUM Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the ser
CVE-2026-93996 6.5 MEDIUM Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read
CVE-2026-94029 6.5 MEDIUM Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension
CVE-2026-87830 Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks.
CVE-2026-85532 Apache WSS4J: Insufficient Validation of Derived-Key Parameters
CVE-2026-88920 Apache WSS4J: SAML Sender-Vouches Authentication Bypass
CVE-2026-89238 Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selecti
CVE-2026-92121 Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an ST
CVE-2026-92899 Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce
CVE-2026-95616 Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.5

IV. Related Vulnerabilities

V. Comments for CVE-2026-102508

No comments yet


Leave a comment