Use After Free Vulnerability in open62541 History Backend
CVE-2026-82623

6.9MEDIUM

Key Information:

Vendor

open62541

Status
Vendor
CVE Published:
31 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-82623?

A vulnerability was identified in the open62541 library, specifically in the History Backend component. This issue arises from the UA_DataValue_backend_copyRange function located in the plugins/historydata/ua_history_data_backend_memory.c file. When exploited, it leads to a use after free condition, allowing an attacker to execute remote code. The vulnerability is publicly known, enabling potential attackers to leverage this flaw against systems running vulnerable versions. The project's response indicates that the vulnerability reporting process was not formally adhered to, raising concerns for users relying on this library.

Affected Version(s)

open62541 1.5.0

open62541 1.5.1

open62541 1.5.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

VULL (VulDB User)
VulDB CNA Team
.