CVE-2026-19259

MEDIUM

MZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_varAccessSpecToObjectReference heap-based overflow

Title source: cna
STIX 2.1

Description

A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varAccessSpecToObjectReference of the file src/iec61850/common/iec61850_common.c of the component MMS Protocol Workflow. Such manipulation of the argument GetNamedVariableListAttributesResponse.itemId leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-387009 | MZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_varAccessSpecToObjectReference heap-based overflow
https://vuldb.com/vuln/387009
Signature, Permissions Required signature permissions-required
VDB-387009 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/387009/cti
Third Party Advisory third-party-advisory
CVE-2026-19259 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-19259
Third Party Advisory third-party-advisory
Submit #865176 | MZ Automation libiec61850 1.6.1 Memory Corruption (Out-of-bounds Read)
https://vuldb.com/submit/865176

Scores

CVSS v3 5.3
EPSS 0.0012
EPSS Percentile 2.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-119 CWE-122
Status published
Products (2)
MZ Automation/libiec61850 1.6.0
MZ Automation/libiec61850 1.6.1
Published Aug 08, 2026
Tracked Since Aug 08, 2026