OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-103432

HIGH · CVSS 8.1 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability exists in the `getupsvar()` function of apcupsd versions up to 3.14.14, affecting components such as upsstats.cgi, multimon.cgi, and upsfstats.cgi. This flaw could allow an attacker to execute arbitrary code, potentially compromising the affected system. Organizations using apcupsd for UPS management should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103432
Severity
HIGH
CVSS
8.1
EPSS
0.38%

Original NVD Description

apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.