SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-16013

MEDIUM · CVSS 5.3 EPSS 0.43% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The liftoff-sr CIPster product is vulnerable to an out-of-bounds read due to a flaw in the CipAppPath::deserialize_symbolic function, which can be exploited remotely. This vulnerability poses a medium risk and has been publicly disclosed, making it critical for organizations using this software to prioritize applying the patch identified as 886a4d090e1c5b0475f0b1c2fe0606a8f0d6a519 to mitigate potential attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16013
Severity
MEDIUM
CVSS
5.3
EPSS
0.43%

Original NVD Description

A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPath::deserialize_symbolic of the file source/src/cip/cipepath.cc. Such manipulation leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The name of the patch is 886a4d090e1c5b0475f0b1c2fe0606a8f0d6a519. A patch should be applied to remediate this issue.