CVE-2026-26008: EVerest has OOB via EVSE ID Indexing Mismatch in OCPP 2.0.1 UpdateAllowedEnergyTransferModes
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that leads to possible remote crash/memory corruption. This is because the CSMS sends UpdateAllowedEnergyTransferModes over the network. Version 2026.2.0 contains a patch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26008?
CVE-2026-26008 is considered a critical vulnerability due to its potential for remote crash and memory corruption.
How do I fix CVE-2026-26008?
To fix CVE-2026-26008, update your EVerest software to version 2026.02.0 or later.
What is the impact of CVE-2026-26008 on EVerest?
The impact of CVE-2026-26008 includes possible remote denial of service and memory corruption due to out-of-bounds access.
Which versions of EVerest are affected by CVE-2026-26008?
Versions of EVerest prior to 2026.02.0 are affected by CVE-2026-26008.
How does CVE-2026-26008 occur in EVerest?
CVE-2026-26008 occurs due to an out-of-bounds access caused by a mismatch in the EVSE ID Indexing during the UpdateAllowedEnergyTransferModes operation.