Blog/vulnerabilities
vulnerabilities

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

September 3, 2026·Source: CISA
0 comments

TL;DR

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities

v3 4.6 OPCFoundation OPCFoundation OPC UA LocalDiscoveryServer (LDS) Execution with Unnecessary Privileges

Background Critical Infrastructure Sectors: Chemical, Energy, Food and Agriculture, Water and Wastewater, Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-77477 An attacker can intercept a high-privilege console window launched during installation of the LDS. The attacker must be able to launch an installer with elevated privileges and have access to the keyboard and display while the installation is taking place. View CVE Details Affected Products OPCFoundation OPC UA LocalDiscoveryServer (LDS) Vendor: OPCFoundation Product Version: OPCFoundation UA-LDS-Installers: <1.04.420 Product Status: known_affected Remediations Mitigation OPCFoundation recommends users update to OPC UA LDS Installers 1.04.420 or later. Mitigation For more information about this vulnerability and its mitigation, see the OPCFoundation security advisory. https://github.com/OPCFoundation/OPC-SecurityAdvisories/tree/latest/csaf/2026/009 Relevant CWE: CWE-250 Execution with Unnecessary Privileges Metrics CVSS Version Base Score Base Severity Vector String

3.1 4.6 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

4.0 2.4 LOW CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Acknowledgments Lukas Schumaker of Rockwell Automation reported this vulnerability to OPCFoundation. OPCFoundation reported this vulnerability to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.c

What Happened

OPCFoundation OPC UA LocalDiscoveryServer (LDS), reported by CISA.

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities

v3 4.6 OPCFoundation OPCFoundation OPC UA LocalDiscoveryServer (LDS) Execution with Unnecessary Privileges

Background Critical Infrastructure Sectors: Chemical, Energy, Food and Agriculture, Water and Wastewater, Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-77477 An attacker can intercept a high-privilege console window launched during installation of the LDS. The attacker must be able to launch an installer with elevated privileges and have access to the keyboard and display while the installation is taking place. View CVE Details Affected Products OPCFoundation OPC UA LocalDiscoveryServer (LDS) Vendor: OPCFoundation Product Version: OPCFoundation UA-LDS-Installers: <1.04.420 Product Status: known_affected Remediations Mitigation OPCFoundation recommends users update to OPC UA LDS Installers 1.04.420 or later. Mitigation For more information about this vulnerability and its mitigation, see the OPCFoundation security advisory. https://github.com/OPCFoundation/OPC-SecurityAdvisories/tree/latest/csaf/2026/009 Relevant CWE: CWE-250 Execution with Unnecessary Privileges Metrics CVSS Version Base Score Base Severity Vector String

3.1 4.6 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

4.0 2.4 LOW CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Acknowledgments Lukas Schumaker of Rockwell Automation reported this vulnerability to OPCFoundation. OPCFoundation reported this vulnerability to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.c

For the full technical details, see the original report.

Why It Matters for Businesses

This development could affect organizations that rely on the impacted technologies or services. Unpatched systems, misconfigured infrastructure, or lack of monitoring can leave businesses exposed to exploitation, data breaches, and regulatory penalties.

How to Check Your Exposure

Run a free scan on NEL Professional's Cyber Risk Scanner to check whether your domain is affected. The scan covers SSL/TLS, security headers, DNS configuration, email authentication, and more across 16 modules.

Check Your Domain Security

Mitigation Steps

  • Patch immediately, Apply vendor patches or updates as soon as they are available.
  • Review configurations, Check firewall rules, access controls, and security headers.
  • Monitor logs, Watch for indicators of compromise (IOCs) related to this threat.
  • Update security policies, Ensure incident response plans cover this type of threat.
  • Run a security scan, Use automated tools to verify your exposure.

Need Expert Help?

If your organization needs help assessing or remediating this issue, hire a verified cybersecurity specialist through NEL Professionals.

Need More Scan Credits?

Get up to 100 scans or unlimited lifetime access starting at $15.

View Plans →

Comments (0)

No comments yet. Be the first to comment!

← Back to Blog