In Eclipse Milo versions 1.0.0 through 1.1.4, OpcUaServerConfig.copy() fails to preserve a configured RoleMapper. On servers that rely on role permissions and construct the running configuration through copy(), sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted to read role-permission metadata, invoke protected methods, or delete protected nodes.
{
"cna_assigner": "eclipse",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58080.json",
"cwe_ids": [
"CWE-862"
]
}[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"129888805742919556529997385732638938781",
"197954823713829520599785012835018461638",
"239941666745209485910912396018623655498",
"108990788959909990370786882980588870822",
"175621742843116358713541903853487275763",
"253966991178098089328898771052475200886",
"256299001000203817617614295929551158743"
]
},
"id": "CVE-2026-58080-256dc095",
"signature_type": "Line",
"source": "https://github.com/eclipse-milo/milo/commit/d51f03e9a75f313ab41c3d68d809f4b922073f1a",
"target": {
"file": "opc-ua-sdk/sdk-server/src/test/java/org/eclipse/milo/opcua/sdk/server/servicesets/impl/DefaultAccessControllerTest.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 650.0,
"function_hash": "221069457620439118668472033062262377418"
},
"id": "CVE-2026-58080-2b3e43b8",
"signature_type": "Function",
"source": "https://github.com/eclipse-milo/milo/commit/d51f03e9a75f313ab41c3d68d809f4b922073f1a",
"target": {
"function": "testCopy",
"file": "opc-ua-sdk/sdk-server/src/test/java/org/eclipse/milo/opcua/sdk/server/OpcUaServerConfigTest.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"42957780144755886509162529226390069935",
"9928560902818701321806059226641726532",
"97455138635007241755855646528875483587",
"209280311923697442659632003574318985261"
]
},
"id": "CVE-2026-58080-34b72780",
"signature_type": "Line",
"source": "https://github.com/eclipse-milo/milo/commit/d51f03e9a75f313ab41c3d68d809f4b922073f1a",
"target": {
"file": "opc-ua-sdk/sdk-server/src/main/java/org/eclipse/milo/opcua/sdk/server/OpcUaServerConfig.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"318433494722677683661413495205270898513",
"25471602053650283061041827248771529544",
"267380098625564446735130307874110659487",
"59099518178588312175172206236948587844",
"316385977314572429679471921850692904136",
"259958080578644479666216471225745913653",
"84632052226953250362386887169143611",
"81225944221934377083483439080477895853",
"231189490301679323521242793051144749725",
"248339041093481332525477971639518519760",
"293076273577212754755326217515793001704",
"336149738834958732791199848572545286561",
"132451529265821577173478535737959679445",
"56503021714465781798788988939405712064",
"39848847705091404904244130972511230615",
"246617531856838646982768551777679438056",
"55516560545018099803976163081162680084",
"71103541741244067820173263634606064661",
"167654766329680905911346570019495793342",
"16030207688895983457666358207488552381",
"334632882248672559247530332871909546785",
"260135419420497356224728925059933944001",
"271870676746170226940271364350367524405",
"252768432680399585459857893129783599551",
"170751909340828458767912190154086180281"
]
},
"id": "CVE-2026-58080-dfb9dfef",
"signature_type": "Line",
"source": "https://github.com/eclipse-milo/milo/commit/d51f03e9a75f313ab41c3d68d809f4b922073f1a",
"target": {
"file": "opc-ua-sdk/sdk-server/src/test/java/org/eclipse/milo/opcua/sdk/server/OpcUaServerConfigTest.java"
}
}
]
"2026-08-07T08:11:20Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58080.json"