CVE-2026-103432
Received Received - Intake

Buffer Overflow in apcupsd via CGI Scripts

Vulnerability report for CVE-2026-103432, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: MITRE

Description

apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apcupsd apcupsd to 3.14.14 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103432 is a stack-based buffer overflow and uninitialized memory disclosure vulnerability in apcupsd through version 3.14.14. It exists in the getupsvar() function within src/cgi/upsfetch.c, which is used by CGI programs like upsstats.cgi, multimon.cgi, and upsfstats.cgi. The vulnerability occurs when attacker-controlled data exceeds fixed-size buffers during data copying from NIS replies, leading to potential crashes or memory leaks.

Detection Guidance

Check if the vulnerable CGI programs (upsstats.cgi, multimon.cgi, upsfstats.cgi) are installed and accessible on your system. Inspect network traffic to the apcupsd Network Information Server (NIS) for unusually long responses or malformed data from client IPs. Review logs for crashes or memory leaks in these CGI processes.

Impact Analysis

This vulnerability can allow remote attackers to crash affected CGI programs, leak sensitive memory contents, or potentially execute arbitrary code. Exploitation requires the CGI to query a malicious or spoofed NIS endpoint, which can be achieved by adding the attacker's IP to hosts.conf or exploiting default-allow behavior. Successful exploitation enables remote, unauthenticated denial of service, information disclosure, and code execution depending on system hardening.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to potential information disclosure. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. A successful exploit could expose sensitive data in memory leaks, violating these regulations and resulting in legal penalties or data breach notifications.

Mitigation Strategies

Disable or remove the vulnerable CGI programs (upsstats.cgi, multimon.cgi, upsfstats.cgi) if not needed. Update to a patched version of apcupsd-cgi if available. Restrict access to the apcupsd NIS by configuring /etc/apcupsd/hosts.conf to allow only trusted IPs. Monitor for unusual network activity or crashes in the CGI processes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103432. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart