CVE-2026-18790: Systerel S2OPC DeleteMonitoredItemsRequest state_machine.c out-of-bounds
A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMacProcessMsgDeleteMonitoredItemsResponse of the file src/ClientServer/frontend/clientwrapper/internal/statemachine.c of the component DeleteMonitoredItemsRequest Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18790?
The severity of CVE-2026-18790 is classified as low, with a score of 3.3.
What is CVE-2026-18790?
CVE-2026-18790 is a vulnerability in Systerel S2OPC that involves an out-of-bounds access in the DeleteMonitoredItemsRequest handler.
How do I fix CVE-2026-18790?
To fix CVE-2026-18790, update Systerel S2OPC to version 1.7.4 or later, where this vulnerability is addressed.
What software is affected by CVE-2026-18790?
CVE-2026-18790 affects Systerel S2OPC versions up to 1.7.3.
What type of vulnerability is CVE-2026-18790?
CVE-2026-18790 is classified as a buffer overflow vulnerability.