CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5652

As cited

Copy frozen at (site build).

vulnerabilities

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

CVE-2026-77477 affects OPCFoundation OPC UA LocalDiscoveryServer (LDS) versions prior to 1.04.420, allowing an attacker with local access and elevated privileges to intercept a high-privilege console window during installation and execute arbitrary commands. The vulnerability carries a CVSS 3.1 base score of 4.6 (medium severity) and requires the attacker to have keyboard and display access during the installation process. OPCFoundation recommends updating to LDS version 1.04.420 or later to remediate the issue.

Why it matters: Organizations deploying OPC UA LDS in critical infrastructure environments (chemical, energy, food and agriculture, water and wastewater, manufacturing) should update to version 1.04.420 immediately to prevent local privilege escalation during installation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

CVE-2026-77477 affects OPCFoundation OPC UA LocalDiscoveryServer (LDS) versions prior to 1.04.420, allowing an attacker with local access and elevated privileges to intercept a high-privilege console window during installation and execute arbitrary commands. The vulnerability carries a CVSS 3.1 base score of 4.6 (medium severity) and requires the attacker to have keyboard and display access during the installation process. OPCFoundation recommends updating to LDS version 1.04.420 or later to remediate the issue.

Why it matters: Organizations deploying OPC UA LDS in critical infrastructure environments (chemical, energy, food and agriculture, water and wastewater, manufacturing) should update to version 1.04.420 immediately to prevent local privilege escalation during installation.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary