OPCFoundation OPC UA LocalDiscoveryServer (LDS) Installer Privilege Escalation
First seen Sep 4, 2026 · Updated Sep 4, 2026 · CVSS 4.6
A local privilege escalation vulnerability exists in the OPC UA LocalDiscoveryServer (LDS) installer prior to version 1.04.420, allowing an attacker with local keyboard/display access during installation to hijack a high-privilege console window and execute arbitrary commands. Exploitation requires local access and user interaction, limiting remote attack potential, but could lead to full system compromise on affected industrial control hosts.
Technical Analysis
CVE-2026-77477 (CWE-250: Execution with Unnecessary Privileges) affects OPCFoundation UA-LDS-Installers versions prior to 1.04.420. During installation, a high-privilege console window is briefly exposed, which a local attacker with keyboard and display access can intercept to run arbitrary commands with elevated privileges. The vulnerability is not remotely exploitable and carries a CVSS v3.1 score of 4.6 (Medium) and CVSS v4.0 score of 2.4 (Low), reflecting the local attack vector, low complexity, and requirement for user interaction. This is an ICS/OT-focused advisory with no known public exploitation; the OPC UA LDS is commonly deployed in industrial environments for service discovery rather than in typical AI agent or LLM tool-use pipelines, so there is no plausible direct impact to AI agent systems from this specific vulnerability.
Affected Systems
OPCFoundation OPC UA LocalDiscoveryServer (LDS) Installers versions prior to 1.04.420, deployed on Windows-based industrial control and automation systems across Chemical, Energy, Food and Agriculture, Water and Wastewater, and Critical Manufacturing sectors worldwide.
Indicators of Compromise
- No specific IOCs published (installer-based local privilege escalation; no known public exploitation reported)
Remediation Steps
- 1
Update Installer
Upgrade to OPC UA LDS Installers version 1.04.420 or later as recommended by OPCFoundation.
- 2
Restrict Installation Access
Limit physical and interactive access to systems during software installation to trusted, authorized personnel only.
- 3
Review OPCFoundation Advisory
Consult the official OPCFoundation security advisory (2026/009) for detailed mitigation guidance.
- 4
Harden Installation Procedures
Use secure installation practices such as running installers in isolated/administrative sessions without shared keyboard/display access.
- 5
Monitor for Anomalous Activity
Report any suspected malicious activity related to installation processes to CISA for tracking and correlation.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.