CVE-2026-54155 | node-opcua up to 2.165.x UserNameIdentityToken authentication handler opcua_server.ts isValidUser improper authentication
A vulnerability has been found in node-opcua up to 2.165.x and classified as critical. This affects the function isValidUser of the file packages/node-opcua-server/source/opcua_server.ts of the component UserNameIdentityToken authentication handler. This manipulation causes improper authentication.
The identification of this vulnerability is CVE-2026-54155. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More