news.mlab.sh
Back to the feed
vulnerability

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

Critical
Summary

A critical vulnerability (CVE-2026-77477) exists in OPCFoundation OPC UA LocalDiscoveryServer (LDS) installers, allowing an attacker to gain control of a high-privilege terminal during installation and execute arbitrary commands. This vulnerability is not exploitable remotely and requires an attacker to be able to launch an installer with elevated privileges and have access to the keyboard and display during installation. The vulnerability affects industrial control systems in critical infrastructure sectors worldwide.

A critical vulnerability (CVE-2026-77477) exists in OPCFoundation OPC UA LocalDiscoveryServer (LDS) installers, allowing an attacker to gain control of a high-privilege terminal during installation and execute arbitrary commands. This vulnerability is not exploitable remotely and requires an attacker to be able to launch an installer with elevated privileges and have access to the keyboard and display during installation. The vulnerability affects industrial control systems in critical infrastructure sectors worldwide.

Affected Products OPCFoundation OPC UA LocalDiscoveryServer (LDS) OPCFoundation OPCFoundation UA-LDS-Installers: <1.04.420

Remediations OPCFoundation recommends users update to OPC UA LDS Installers 1.04.420 or later.

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.

Read the full article at CISA Advisories