CVE-2026-19259
MEDIUMMZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_varAccessSpecToObjectReference heap-based overflow
Title source: cnaDescription
A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varAccessSpecToObjectReference of the file src/iec61850/common/iec61850_common.c of the component MMS Protocol Workflow. Such manipulation of the argument GetNamedVariableListAttributesResponse.itemId leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References (6)
Core 6
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-387009 | MZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_varAccessSpecToObjectReference heap-based overflow
https://vuldb.com/vuln/387009
Signature, Permissions Required signature
permissions-required
VDB-387009 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/387009/cti
Third Party Advisory third-party-advisory
CVE-2026-19259 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-19259
Third Party Advisory third-party-advisory
Submit #865176 | MZ Automation libiec61850 1.6.1 Memory Corruption (Out-of-bounds Read)
https://vuldb.com/submit/865176
Issue Tracking issue-tracking
https://github.com/mz-automation/libiec61850/issues/599
Exploit exploit
https://github.com/user-attachments/files/29190426/PoC.zip
Scores
CVSS v3
5.3
EPSS
0.0012
EPSS Percentile
2.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-119
CWE-122
Status
published
Products (2)
MZ Automation/libiec61850
1.6.0
MZ Automation/libiec61850
1.6.1
Published
Aug 08, 2026
Tracked Since
Aug 08, 2026