CVE-2026-9158: Use After Free
Published Jun 18, 2026
·Updated
In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).
Affected Software
2 affected components
Eclipse 4diac Forte>=3.0.0<=3.1.0
Eclipse 4diac Forte>=3.0.0<=3.1.0
Event History
Jun 18, 2026
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-9158?
CVE-2026-9158 has a medium severity rating of 5.2 according to the CVSS scoring system.
2
What software is affected by CVE-2026-9158?
CVE-2026-9158 affects Eclipse 4diac FORTE versions 3.0.0 to 3.1.0.
3
How do I fix CVE-2026-9158?
To fix CVE-2026-9158, you should update Eclipse 4diac FORTE to the latest version that addresses this vulnerability.
4
What type of vulnerability is CVE-2026-9158?
CVE-2026-9158 is classified as a use after free vulnerability.
5
What can be exploited in CVE-2026-9158?
CVE-2026-9158 can be exploited by sending a specially crafted DELETE connection command to the management interface, leading to access of freed memory.