Heap-Based Buffer Overflow Vulnerability in o6 open62541 Software
CVE-2026-18784
Key Information:
Badges
What is CVE-2026-18784?
A vulnerability exists in the o6 open62541 software that can lead to a heap-based buffer overflow through the UA_Client_readNodeClassAttribute function within the src/client/ua_client_highlevel.c file. This flaw necessitates local exploitation, allowing attackers to manipulate affected system behavior. While public exploits exist, the project management has indicated that this does not adhere to official vulnerability reporting protocols, which raises concerns over the software's security posture and ongoing risk for users.
Affected Version(s)
open62541 1.5.0
open62541 1.5.1
open62541 1.5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
