CVE-2026-18784: o6 open62541 ua_client_highlevel.c UA_Client_readNodeClassAttribute heap-based overflow
A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UAClientreadNodeClassAttribute of the file src/client/uaclienthighlevel.c. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18784?
The severity of CVE-2026-18784 is classified as medium with a score of 5.3.
How do I fix CVE-2026-18784?
To fix CVE-2026-18784, update to the latest version of o6 open62541 that addresses the heap-based buffer overflow.
What type of vulnerability is CVE-2026-18784?
CVE-2026-18784 is identified as a buffer overflow vulnerability.
Is local access required to exploit CVE-2026-18784?
Yes, local access is required to exploit the vulnerability listed in CVE-2026-18784.
Who is affected by CVE-2026-18784?
Users of o6 open62541 versions up to 1.5.5 are affected by CVE-2026-18784.