CVE-2026-67856: High severity open62541 open62541 vulnerability
Published Aug 4, 2026
·Updated
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests
Affected Software
1 affected component
open62541 open62541<=1.5.5
Event History
Aug 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-67856?
The severity of CVE-2026-67856 is rated as 29, indicating a significant risk of denial of service.
2
How do I fix CVE-2026-67856?
To fix CVE-2026-67856, upgrade to open62541 version 1.5.6 or later that addresses this vulnerability.
3
What impact does CVE-2026-67856 have on systems?
CVE-2026-67856 allows remote attackers to disrupt services, leading to denial of service due to crafted requests.
4
Which versions of open62541 are affected by CVE-2026-67856?
CVE-2026-67856 affects open62541 v.1.5.5 and earlier versions.
5
Is there a way to mitigate CVE-2026-67856 without upgrading?
While upgrading is recommended, implementing strict input validation on subscription requests may help mitigate the effects of CVE-2026-67856.