CVE-2023-26150: Freeopcua Opcua-Asyncio
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session.
Affected products
- Freeopcua Opcua-Asyncio: before 0.9.96 (fixed in 0.9.96)
Published 2023-10-03. Last modified 2026-06-17.