CVE-2026-103436
Received Received - Intake

apcupsd Uninitialized Memory Disclosure in CGI Scripts

Vulnerability report for CVE-2026-103436, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: MITRE

Description

apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three whitespace-separated tokens, sscanf("%*s %*s %s", answer) performs no assignment but the function returns success, and thus the caller prints the uninitialized destination buffer into the HTTP response.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apcupsd apcupsd to 3.14.14 (inc)
apcupsd apcupsd 3.14.14

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-457 The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in apcupsd through 3.14.14 involves uninitialized stack memory disclosure in the getupsvar() function used by CGI programs like upsstats.cgi. When a STATUS line has fewer than three tokens, sscanf fails to assign a value but returns success, causing the function to print an uninitialized buffer in the HTTP response.

Detection Guidance

Check if the vulnerable CGI binaries (upsstats.cgi, multimon.cgi, upsfstats.cgi) are present on your system. Inspect the source code of upsfetch.c for the getupsvar() function to confirm the uninitialized memory disclosure issue. Monitor network traffic for unexpected HTML responses containing uninitialized stack data from these CGI programs.

Impact Analysis

An attacker could exploit this to leak sensitive memory contents or crash CGI processes, leading to denial of service. If combined with other flaws, it might enable remote code execution. Exploitation requires the CGI to query a malicious NIS endpoint, which can be achieved by manipulating hosts.conf or default-allow settings.

Compliance Impact

This vulnerability could lead to information disclosure, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Unauthorized memory leaks may expose sensitive data, risking compliance penalties.

Mitigation Strategies

Upgrade to the latest version of apcupsd if a patched release is available. Remove or restrict access to the vulnerable CGI binaries (upsstats.cgi, multimon.cgi, upsfstats.cgi) if not needed. Ensure /etc/apcupsd/hosts.conf restricts allowed NIS endpoints to trusted IPs only. Apply network-level controls to block unauthorized access to the apcupsd Network Information Server (NIS).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103436. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart