CVE-2026-67857
📛 CVE Title
CVE-2026-67857
Description
open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- mitre
- CVSS severity
- HIGH
- CVSS score
- 7.5 / 10
- CVSS vector
CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N- Effective score
- 7.5 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- 2026-07-30
- Published
- 2026-08-04 00:00 UTC
- Last updated
- 2026-08-05 14:31 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/67xxx/CVE-2026-67857.json
- Linked Threat
- CVE-2026-67857 — CVE-2026-67857
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-08-04 22:17:15 UTC
- NVD last modified
- 2026-08-05 15:17:06 UTC
- NVD CVSS v3.1
- 7.5 / 10 HIGH source: cve@mitre.org
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 3.6 / 10
- EPSS score
- 0.0035 (probability of exploitation in next 30 days)
- EPSS percentile
- 27.67% vs all CVEs — higher = more likely to be exploited, as of 2026-08-05
NVD-assigned CWE(s):
CWE-125
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-08-06 02:35 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-52967 - Assigner
- mitre
- Published
- Aug 4, 2026, 12:00:00 AM
- Updated
- Aug 5, 2026, 2:31:49 PM
- EUVD base score (CVSS 3.1)
-
7.5 / 10
CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N - EUVD-reported EPSS
- 0.0000
- Vendors
- n/a
- Products
-
n/a (n/a)
- Aliases
-
GHSA-2mh5-cmr8-pwvp
ENISA description: open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
EUVD references (5)
- https://github.com/open62541/open62541/issues/8104
- https://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_connect.c
- https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect.c
- https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect_loop.c
- https://github.com/gff-cw/information/issues/9
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| n/a | n/a |
n/a (affected)
|
— |
Vendor references (5)
References embedded in the original CVE record by the assigning CNA.
- https://github.com/open62541/open62541/issues/8104
- https://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_connect.c
- https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect.c
- https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect_loop.c
- https://github.com/gff-cw/information/issues/9
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (6)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/gff-cw/information/issues/9 cve@mitre.org
- https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect.c cve@mitre.org
- https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect_loop.c cve@mitre.org
- https://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_connect.c cve@mitre.org
- https://github.com/open62541/open62541/issues/8104 cve@mitre.org
- https://github.com/open62541/open62541/issues/8104 134c704f-9b21-4f2e-91b3-4a467353bcc0
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:access.redhat.com
A flaw was found in open62541. A remote attacker could exploit an out-of-bounds read vulnerability in the client-side function responseReadNamespacesArray () by sending a specially crafted network packet. This could lead to a denial of service, causing the application to crash and become unavailable.
2026-08-06 01:15 UTC -
web:compliancehub.wiki
CVE - 2026 -18577 bypasses the N-able N-central patch , giving admin access and endpoint pivot via Take Control. KEV deadline 6 August 2026 — response and IOCs.
2026-08-06 01:15 UTC -
web:cybersecuritynews.com
Apple has released iOS 26.6 and iPadOS 26.6 to fix security flaws that could enable kernel code execution, root access, and sandbox escape.
2026-08-06 01:15 UTC -
web:nvd.nist.gov
CVE - 2026 -18577 Detail Description An incomplete patch for CVE - 2026 -18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
2026-08-06 01:15 UTC -
web:status.n-able.com
If you identify any of these, contact N-able support immediately and engage your own security team. Supported Upgrade Paths Upgrade directly to 2026.3.1 from 2025.4 2026.1 2026.2 2026.3 If you are on an older version, we recommend going to any of the builds above. Then upgrade to this Hotfix version ASAP. If you are unsure of what to do, you can contact support directly. Do I need to update my ...
2026-08-06 01:15 UTC -
web:techcommunity.microsoft.com
We wanted to tell you how to address the Exchange Server May 2026 vulnerability CVE - 2026 -42897.
2026-08-06 01:15 UTC -
web:vulners.com
CVE-2026-67857 🗓️ 03 Aug 2026 17:00:00 Reported by mitre Type cve 🔗 web.nvd.nist.gov 👁 11 Views
2026-08-06 01:15 UTC -
web:www.n-able.com
As our investigation progressed, we determined the vulnerability affected all versions of N‑central and released a comprehensive hotfix (2026.3.1.7) on August 2: N‑central 2026.3 Hotfix 1 - Mitigation for CVE - 2026 -18577.
2026-08-06 01:15 UTC -
web:www.oracle.com
Additional CVEs addressed are: The patch for CVE - 2026 -34481 also addresses CVE - 2026 -34477, CVE - 2026 -34478, CVE - 2026 -34479, and CVE - 2026 -34480. Oracle Fusion Middleware Risk Matrix This Critical Security Patch Update contains 106 new security patches for Oracle Fusion Middleware. 53 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a ...
2026-08-06 01:15 UTC -
web:www.theregister.com
CVE - 2026 -18577 is related to an earlier flaw, CVE - 2026 -18556, patched in N-central 2026.2. According to N-able, that fix left another route to exploitation, which attackers began abusing late last month. CISA gave Federal Civilian Executive Branch agencies until August 6 to remediate the flaw. Under Binding Operational Directive 26-04, CISA can impose a three-day deadline on vulnerabilities it ...
2026-08-06 01:15 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-67857.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-67857",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-05T14:31:17.935192Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-125",
"description": "CWE-125 Out-of-bounds Read",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T14:31:49.820Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/open62541/open62541/issues/8104"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-04T21:21:25.605Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://github.com/open62541/open62541/issues/8104"
},
{
"url": "https://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_connect.c"
},
{
"url": "https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect.c"
},
{
"url": "https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect_loop.c"
},
{
"url": "https://github.com/gff-cw/information/issues/9"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-67857",
"datePublished": "2026-08-04T00:00:00.000Z",
"dateReserved": "2026-07-30T00:00:00.000Z",
"dateUpdated": "2026-08-05T14:31:49.820Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}