SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2026-6899

It might allow connection between an OPC UA client and server using a revoked certificate.

MEDIUM 5.6EPSS 0.11%

Does this matter?

Lower severity and a low EPSS score (0.11%). Track it; it rarely justifies an emergency change on its own.

Description

Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.

CVSS 3.1
5.6 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
0.11% probability · 1th percentile
CISA KEV
Not listed
Weakness
CWE-299
Source
cve@gitlab.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.