CVE-2026-103432: Buffer Overflow
Published Sep 30, 2026
·Updated
apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.
Affected Software
1 affected component
Apcupsd Apcupsd<=3.14.14
Event History
Sep 30, 2026
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates network access is required, while no privileges or user interaction are required. Exploitation is rated as high complexity.
2
Which deployments should be considered affected?
Apcupsd versions through 3.14.14 should be considered affected where the CGI code is in use, including upsstats.cgi, multimon.cgi, or upsfstats.cgi.