CVE-2026-6899
Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.6
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS probability
- 0.11%
- CWE
- CWE-299
- Published
- 2026-06-09
- Last modified
- 2026-06-09
Affected products
- Systerel S2OPC
Weakness type
Related vulnerabilities
- CVE-2026-86231 — mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation
- CVE-2026-61699 — nebula-mesh: Certificate revocation is never enforced at the mesh
- CVE-2026-56821 — Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
- CVE-2026-9636 — Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Module – Certificate Revocation List Vulnerability
- CVE-2026-4428 — CRL Distribution Point Scope Check Logic Error in AWS-LC
- CVE-2025-11955 — Incorrect validation of OCSP certificates in TheGreenBow VPN Client Windows Enterprise
- CVE-2025-36057 — IBM Cognos Analytics Mobile (iOS) authentication bypass
- CVE-2025-3085 — MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked