CVE-2026-67856: High severity open62541 open62541 vulnerability

Published Aug 4, 2026
·
Updated

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests

Affected Software

1 affected component
open62541 open62541<=1.5.5

Event History

Aug 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-67856?

The severity of CVE-2026-67856 is rated as 29, indicating a significant risk of denial of service.

2

How do I fix CVE-2026-67856?

To fix CVE-2026-67856, upgrade to open62541 version 1.5.6 or later that addresses this vulnerability.

3

What impact does CVE-2026-67856 have on systems?

CVE-2026-67856 allows remote attackers to disrupt services, leading to denial of service due to crafted requests.

4

Which versions of open62541 are affected by CVE-2026-67856?

CVE-2026-67856 affects open62541 v.1.5.5 and earlier versions.

5

Is there a way to mitigate CVE-2026-67856 without upgrading?

While upgrading is recommended, implementing strict input validation on subscription requests may help mitigate the effects of CVE-2026-67856.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203