TL;DR
The Apache Software Foundation disclosed CVE-2026-102508, a critical Apache PLC4X vulnerability in its OPC UA driver, on September 30, 2026. It scores 9.2 under CVSS 4.0. An attacker in a network position between client and server can impersonate the server and steal user credentials.
- CVE: CVE-2026-102508
- CVSS: 9.2 (Critical · CVSSv4)
- Product: Apache Software Foundation Apache PLC4X
- Affected: 0.9.0
- Impact: Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade
- Status: No confirmed exploitation yet
- Patched in: 1.0.0
- Action: Update to 1.0.0 now
Turn Apache CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysWhy This Apache PLC4X Vulnerability Matters
Apache PLC4X is a set of libraries for talking to industrial programmable logic controllers (PLCs). It supports many protocols through one shared API. OPC UA is a common standard in factories and plants. When its secure channel fails, an attacker can read or alter commands and data flowing to industrial systems.
How the Attack Works
The flaw breaks three protections at once. According to the Apache PLC4X security advisory, the driver allows an attacker “to impersonate the OPC UA server and to read, forge or modify secure-channel traffic.”
Broken Signature and Certificate Checks
In versions 0.9.0 through 0.11.0, the driver only logs a failed signature check and never enforces it. It also takes the server certificate from an unauthenticated discovery response. Later, in 0.12.0 through 0.13.1, the signature check runs backwards. It rejects valid signatures and accepts invalid ones.
Silent Downgrades
Every affected version defaults to a security policy of None. Newer builds also fall back to weaker settings without warning.
Affected Versions and Exploitation Status
The issue affects the plc4j-driver-opcua package from 0.9.0 before 1.0.0. Abhinav Agarwal reported it in July 2026. No exploitation or public proof-of-concept has been confirmed.
Patch and Mitigation Steps
Upgrade to Apache PLC4X 1.0.0, released on September 7, 2026. It verifies signatures, requires a trusted or pinned server certificate, and defaults to Basic256Sha256 with SignAndEncrypt. Apache warns that users “checking only for one of these mechanisms may wrongly conclude they are unaffected.” Treat any older build as exposed to this Apache PLC4X vulnerability.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!