CVE-2026-41502: BACnet Stack: Off-by-One Out-of-Bounds Read in ReadPropertyMultiple Object ID Decoder
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of-bounds read vulnerability in bacnet-stack's ReadPropertyMultiple service decoder allows unauthenticated remote attackers to read one byte past an allocated buffer boundary by sending a crafted RPM request with a truncated object identifier. The vulnerability is in rpmdecodeobjectid(), which checks apdulen < 5 but then accesses all 6 byte positions (indices 0-5) — consuming 1 byte for the context tag, 4 bytes for the object ID, then reading apdu[5] for the opening tag check. A 5-byte input passes the length check but causes a 1-byte OOB read, leading to crashes on embedded BACnet devices. The vulnerability exists in src/bacnet/rpm.c and affects any deployment that enables the ReadPropertyMultiple confirmed service handler (enabled by default in the reference server). This vulnerability is fixed in 1.4.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41502?
CVE-2026-41502 is rated as a medium-severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2026-41502?
To fix CVE-2026-41502, upgrade BACnet Stack to version 1.4.3 or later.
What causes the CVE-2026-41502 vulnerability?
The CVE-2026-41502 vulnerability is caused by an off-by-one out-of-bounds read in the ReadPropertyMultiple service decoder.
Which versions of BACnet Stack are affected by CVE-2026-41502?
BACnet Stack versions prior to 1.4.3 are affected by CVE-2026-41502.
What is the impact of CVE-2026-41502 on systems?
The impact of CVE-2026-41502 may involve potential unauthorized access to sensitive information due to an out-of-bounds read.