important · Physical — Windows
A person at the console during OPC UA LDS installation can execute commands with the installer's elevated privileges.
Affects
OPC UA Local Discovery Server, discovery infrastructure installed as Windows services on industrial and engineering systems.
The path exists only while an administrator runs a vulnerable installer elevated and someone has physical access to its keyboard and display.
Detail and 4 sources
The pre-1.04.420 installer exposes an interactive elevated console that accepts the person's commands.
OPC UA LDS 1.04.420 addresses the issue.
Sources
ResearchUnified Architecture - OPC FoundationCode / PoCCSAF/csaf_files/OT/white/2026/icsa-26-246-01.json at develop · cisagov/CSAF · GitHubCode / PoCOPC-SecurityAdvisories/csaf/2026/009 at latest · OPCFoundation/OPC-SecurityAdvisories · GitHubCode / PoCGitHub - OPCFoundation/UA-LDS-Installers · GitHub