CVE-2026-18582
Received Received - Intake

Memory Corruption in libiec61850 Report Handler

Vulnerability report for CVE-2026-18582, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: VulDB

Description

A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Reporting_RCBWriteAccessHandler of the file src/iec61850/server/mms_mapping/reporting.c of the component Report Sending Path Handler. The manipulation results in free of memory not on the heap. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.2 is able to resolve this issue. The patch is identified as 5b2a69f44256b8548927d8afdd7ac5f5381abe1e. It is suggested to upgrade the affected component. The vendor was contacted early about this disclosure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mz-automation libiec61850 to 1.6.1 (inc)
mz-automation libiec61850 1.6.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-590 The product calls free() on a pointer to memory that was not allocated using associated heap allocation functions such as malloc(), calloc(), or realloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a memory corruption issue in the mz-automation libiec61850 library up to version 1.6.1. It occurs in the Reporting_RCBWriteAccessHandler function within the Report Sending Path Handler component. The flaw allows attackers to free memory improperly, potentially leading to crashes or arbitrary code execution. The vulnerability is remotely exploitable and a public exploit is available.

Detection Guidance

Detecting this vulnerability requires checking the version of mz-automation libiec61850 installed on your system. Use commands like 'dpkg -l libiec61850' or 'rpm -qa | grep libiec61850' to verify the installed version. If the version is up to 1.6.1, the system is vulnerable.

Impact Analysis

If you use the affected library, an attacker could exploit this flaw to cause denial-of-service conditions or execute arbitrary code on your system. This could lead to system instability, unauthorized access, or data breaches depending on the application's context.

Mitigation Strategies

Upgrade mz-automation libiec61850 to version 1.6.2 or later immediately. Apply the patch identified as 5b2a69f44256b8548927d8afdd7ac5f5381abe1e if available. Isolate affected systems from the network if immediate upgrading is not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18582. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart