Critical severity9.8NVD Advisory· Published Aug 6, 2026· Updated Aug 31, 2026
CVE-2026-67870
CVE-2026-67870
Description
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
1- Open62541: 14 Critical and High-Severity Vulnerabilities Disclosed TogetherVypr Intelligence · Aug 6, 2026