securityonline.info 30 Sept 2026, 08:43 UTC

Critical Apache PLC4X Flaw Enables OPC UA Server Impersonation

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical flaw in the Apache PLC4X OPC UA driver has been disclosed as CVE-2026-102508, with a CVSS v4 score of 9.2. The advisory notes that an attacker positioned between a client and server could impersonate the OPC UA server and read, forge or modify secure-channel traffic, enabling potential credential theft and manipulation of commands to industrial systems.

The vulnerability affects the plc4j-driver-opcua component from version 0.9.0 up to, but not including, 1.0.0, and stems from multiple weaknesses in how the driver handles signatures and certificates.

Specifically, the flaw includes broken signature and certificate checks and silent downgrades in default security settings. In older releases (0.9.0–0.11.0), the system would log a failed signature check without enforcing it, while newer builds (0.12.0–0.13.1) reverse the signature checks, accepting invalid signatures and rejecting valid ones. Added to the risk is a default security policy of None in affected versions, with subsequent builds potentially downgrading security settings without warning.

Abhinav Agarwal first reported the issue in July 2026, but there has been no confirmed exploitation or public PoC at the time of reporting.

The guidance is clear: upgrade to PLC4X 1.0.0, released on 7 September 2026, which enforces signature checks, requires a trusted or pinned server certificate, and defaults to Basic256Sha256 with SignAndEncrypt. Any older build should be treated as exposed until updated.

View full article

Article by CyberSIXT