VYPR
advisoryPublished Sep 3, 2026· 1 source

CISA Warns of Local Privilege Escalation Vulnerability in OPCFoundation OPC UA LocalDiscoveryServer

A critical vulnerability in OPCFoundation's OPC UA LocalDiscoveryServer (LDS) allows local attackers to execute arbitrary commands with high privileges during installation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a new advisory detailing a critical vulnerability affecting OPCFoundation's OPC UA LocalDiscoveryServer (LDS) software. Identified as CVE-2026-77477, the flaw resides in versions prior to 1.04.420 and poses a significant risk to industrial control systems (ICS) environments.

The vulnerability stems from an attacker's ability to intercept a high-privilege console window that is launched during the installation process of the LocalDiscoveryServer. This requires the attacker to have local access, the capability to launch an installer with elevated privileges, and physical or remote console access to the affected system while the installation is in progress. Successful exploitation could grant an attacker the ability to execute arbitrary commands, ultimately leading to the complete takeover of a high-privilege terminal.

This vulnerability is categorized under CWE-250, 'Execution with Unnecessary Privileges,' highlighting the potential for unauthorized command execution. The CVSS v3.1 base score for CVE-2026-77477 is rated as 4.6 (MEDIUM), with a CVSS v4.0 score of 2.4 (LOW). While not remotely exploitable, its local nature combined with the potential for high-privilege execution makes it a serious concern for organizations utilizing OPC UA technology.

OPC UA (Open Platform Communications Unified Architecture) is a widely adopted industrial communication standard used across various critical infrastructure sectors, including Chemical, Energy, Food and Agriculture, Water and Wastewater, and Critical Manufacturing. The affected OPCFoundation UA-LDS-Installers are deployed globally, making the potential impact of this vulnerability widespread.

OPCFoundation has addressed this vulnerability by releasing version 1.04.420 of the OPC UA LocalDiscoveryServer installers. The company strongly recommends that all users update to this latest version or a later release to mitigate the risk. Further details and security advisories can be found on OPCFoundation's GitHub repository dedicated to security advisories.

CISA advises organizations to implement defensive measures to minimize the risk of exploitation. This includes performing thorough impact analyses and risk assessments before deploying any security enhancements. CISA also emphasizes the importance of adhering to recommended cybersecurity practices for control systems, such as implementing defense-in-depth strategies and robust intrusion detection and mitigation measures.

While no public exploitation of this specific vulnerability has been reported to CISA at this time, the advisory serves as a proactive warning. The vulnerability's local execution requirement means that attackers would likely need to gain initial access to a network or system through other means before leveraging CVE-2026-77477. Organizations are encouraged to review their security postures and ensure that all systems running affected versions of OPC UA LDS are promptly updated.

This advisory was initially published by CISA on September 3, 2026. Lukas Schumaker of Rockwell Automation is credited with reporting this vulnerability to OPCFoundation, underscoring the collaborative nature of vulnerability disclosure within the industrial cybersecurity community.

Synthesized by Vypr AI