CVE-2026-67863: Use After Free
Published Aug 5, 2026
·Updated
In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UASubscriptionlocalPublish continues to use the current UANotification after a callback invokes UAServerdeleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.
Affected Software
1 affected component
open62541 open62541=1.5.5
Event History
Aug 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·11:16 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-67863?
CVE-2026-67863 has a high severity rating of 7.5.
2
What is the main issue described in CVE-2026-67863?
CVE-2026-67863 describes a server-side use-after-free vulnerability in the local MonitoredItem callback path of open62541.
3
How can I mitigate the risk of CVE-2026-67863?
To mitigate the risk of CVE-2026-67863, update to the latest version of open62541 that addresses this vulnerability.
4
In which software is CVE-2026-67863 found?
CVE-2026-67863 is found in open62541 version 1.5.5.
5
What type of vulnerability is CVE-2026-67863 classified as?
CVE-2026-67863 is classified as a Use After Free vulnerability.