Skip to content
VulniPulse
Advisory severityCritical9.2Apache Software Foundation

Critical [CVE-2026-102508] Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client

This critical-severity Apache Software Foundation advisory covers CVE-2026-102508 affecting Apache PLC4X.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-102508 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Apache Software FoundationUnclassified
Open source advisory

Android app · Google Play

Monitor future Apache Software Foundation CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client.

The defect manifests differently depending on the version:

  • In 0.9.0 through 0.11.0 a failed message-signature check is only logged and never enforced, and there is no mechanism to verify the server certificate: it is taken from the unauthenticated GetEndpoints discovery response and used to encrypt the user's password.
  • In 0.12.0 through 0.13.1 the signature check is inverted (valid signatures are rejected, invalid ones accepted), and server certificates are accepted without a trust anchor by default.
  • In all affected versions the default security policy is None. Starting with 0.12.0 the driver additionally continues silently at a weaker security policy than the one configured, and starting with 0.13.0 endpoint selection prefers the weakest matching endpoint.

Users checking only for one of these mechanisms may wrongly conclude they are unaffected.

This issue affects Apache PLC4X: from 0.9.0 before 1.0.0.

Users are recommended to upgrade to version 1.0.0, which fixes the issue.

Affected versions
  • 0.9.0 before 1.0.0
  • through 0.11.0
  • through 0.13.1

Official advisory · high-confidence parse· fetched 6 days ago·verify at source

Fixed versions
  • 1.0.0

Official advisory · high-confidence parse· fetched 6 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Users are recommended to upgrade to version 1.0.0, which fixes the issue.

Official advisory · high-confidence parse· fetched 6 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.