A vulnerability in the OPCFoundation OPC UA LocalDiscoveryServer (LDS) could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. This flaw is exploitable via a high-privilege console window launched during installation of the LDS, requiring the attacker to have access to the keyboard and display while the installation is taking place. The vulnerability has been assigned CVE-2026-77477 with a CVSS score of 4.6, indicating a medium severity risk. Successful exploitation could lead to significant business impact, particularly in critical infrastructure sectors such as chemical, energy, food and agriculture, water and wastewater, and critical manufacturing.
We recommend you to update OPCFoundation OPC UA LocalDiscoveryServer (LDS) to the latest available version.[/subscribe_to_unlock_form]
A vulnerability in the OPCFoundation OPC UA LocalDiscoveryServer (LDS) could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. This flaw is exploitable via a high-privilege console window launched during installation of the LDS, requiring the attacker to have access to the keyboard and display while the installation is taking place. The vulnerability has been assigned CVE-2026-77477 with a CVSS score of 4.6, indicating a medium severity risk. Successful exploitation could lead to significant business impact, particularly in critical infrastructure sectors such as chemical, energy, food and agriculture, water and wastewater, and critical manufacturing.
We recommend you to update OPCFoundation OPC UA LocalDiscoveryServer (LDS) to the latest available version.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]