← Back to search

CVE-2026-67860

7.5 HIGHpublic exploit available

Published 2026-08-04 · Updated 2026-08-05

AI risk analysis

Summary
The flaw is a heap-based buffer overflow in open62541 1.5.5's HistoryRead path when using the default memory backend history database, allowing potential code execution if exploited.
Exploitability
Exploitation requires specific configuration and access to the affected version of open62541, making it moderately difficult but feasible with the right conditions.
Blast radius
If exploited, this vulnerability could lead to full system compromise on devices running the affected software, potentially impacting industrial control systems or other critical infrastructure.
Prioritized remediation
Upgrade to a non-vulnerable version of open62541 or disable the default history database feature until a patch is available.
buffer-overflowicsmemory-backendheap-overflow

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-122

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.