Junglewise Threat Intelligence

CVE-2026-18257: Systerel S2OPC Improper Certificate Validation in CycloneCrypto

CVE-2026-18257 · Severity: medium · CVSS 5.6 · Published 2026-07-29

Technologies: Systerel S2OPC. Vendors: Systerel.

Executive brief

A security flaw exists in S2OPC, an open-source implementation of the OPC UA communication protocol used in industrial automation. The software fails to properly check if a master security certificate has expired, which could allow unauthorized or outdated systems to be incorrectly trusted. This could potentially lead to unauthorized access or data manipulation within industrial control environments.

Technical details

An improper certificate validation vulnerability (CWE-295) exists in the CycloneCrypto cryptographic wrapper of S2OPC. The root cause is a failure to correctly verify the validity period of a root issuer certificate during the chain of trust validation. A remote attacker could potentially present a certificate signed by an expired or otherwise invalid root CA, which the system would incorrectly accept as trusted. This affects S2OPC versions 1.5.0 through 1.9.x and is addressed in version 2.0.0. Exploitation requires a high-complexity environment where the attacker can intercept or initiate network communication.

Affected products

  • Systerel S2OPC >= 1.5.0, < 2.0.0

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References

Related threats