CVE-2026-15690

LOW

open62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereference

Title source: cna
STIX 2.1

Description

A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the component Shared Client Library. Such manipulation of the argument Server_NamespaceArray leads to null pointer dereference. The attack can be executed remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit is publicly available and might be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-378237 | open62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereference
https://vuldb.com/vuln/378237
Signature, Permissions Required signature permissions-required
VDB-378237 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/378237/cti
Third Party Advisory third-party-advisory
CVE-2026-15690 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15690
Third Party Advisory third-party-advisory
Submit #855996 | open62541 Project open62541 master (commit ca356b088ada7dee824d1b4acd07c1ff07ce242b) out-of-bounds read
https://vuldb.com/submit/855996

Scores

CVSS v3 3.1
EPSS 0.0027
EPSS Percentile 18.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-404 CWE-476
Status published
Products (6)
None/open62541 1.5.0
None/open62541 1.5.1
None/open62541 1.5.2
None/open62541 1.5.3
None/open62541 1.5.4
None/open62541 1.5.5
Published Jul 14, 2026
Tracked Since Jul 14, 2026