CVE-2026-15690
LOWopen62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereference
Title source: cnaDescription
A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the component Shared Client Library. Such manipulation of the argument Server_NamespaceArray leads to null pointer dereference. The attack can be executed remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit is publicly available and might be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.
References (6)
Core 6
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-378237 | open62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereference
https://vuldb.com/vuln/378237
Signature, Permissions Required signature
permissions-required
VDB-378237 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/378237/cti
Third Party Advisory third-party-advisory
CVE-2026-15690 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15690
Third Party Advisory third-party-advisory
Submit #855996 | open62541 Project open62541 master (commit ca356b088ada7dee824d1b4acd07c1ff07ce242b) out-of-bounds read
https://vuldb.com/submit/855996
Exploit exploit
issue-tracking
https://github.com/open62541/open62541/issues/8104
Product product
https://github.com/open62541/open62541/
Scores
CVSS v3
3.1
EPSS
0.0027
EPSS Percentile
18.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-404
CWE-476
Status
published
Products (6)
None/open62541
1.5.0
None/open62541
1.5.1
None/open62541
1.5.2
None/open62541
1.5.3
None/open62541
1.5.4
None/open62541
1.5.5
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026