Heap-based Out-of-Bounds Write Vulnerability in S2OPC 1.7.3
CVE-2026-67868

9.8CRITICAL

Key Information:

Vendor

Systerel

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-67868?

A heap-based out-of-bounds write vulnerability is present in S2OPC version 1.7.3, specifically within the server-side EventFilter handling during the CreateMonitoredItems process. This flaw permits an attacker to exploit the vulnerability remotely, potentially leading to arbitrary code execution on affected systems. Given its nature, it is crucial for users and administrators of S2OPC to apply appropriate mitigations and stay informed about potential patches.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.