AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18785

MEDIUM · CVSS 5.3 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A use-after-free vulnerability exists in the UA_Client_getRemoteDataTypes function of the open62541 library, potentially allowing local attackers to manipulate memory and execute arbitrary code. This flaw could compromise the integrity and availability of applications utilizing this library. Organizations using open62541 should prioritize patching or mitigating this vulnerability to safeguard their systems against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18785
Severity
MEDIUM
CVSS
5.3
EPSS
0.11%

Original NVD Description

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. The project closed the issue report, stating that this is not the official way to report a security vulnerability.