CVE-2026-19108: Use After Free in MZ Automation libiec61850
A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The manipulation results in use after free. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 1.6.2 is sufficient to fix this issue. The patch is identified as 486fd57f3aed65bb9d636ff00f9ddce2e450b168. Upgrading the affected component is advised.
AI Analysis
Technical Summary
CVE-2026-19108 is a use-after-free vulnerability found in the deleteDataSetValuesShadowBuffer function of the src/iec61850/server/mms_mapping/reporting.c file in MZ Automation libiec61850 up to version 1.6.1. The vulnerability affects the URCB Revalidation component and requires local access with low privileges to exploit. Exploit code has been publicly disclosed. The vulnerability is addressed by upgrading to version 1.6.2, with the patch identified by commit 486fd57f3aed65bb9d636ff00f9ddce2e450b168.
Potential Impact
Successful exploitation can lead to limited confidentiality, integrity, and availability impacts due to use-after-free memory corruption. The attack requires local access and low privileges, reducing the overall risk. The CVSS 3.1 base score is 5.3 (low severity). No known active exploitation in the wild has been reported.
Mitigation Recommendations
Upgrade MZ Automation libiec61850 to version 1.6.2 or later to remediate this vulnerability. This official fix fully addresses the use-after-free issue. No additional mitigation steps are required beyond applying the patch.
CVE-2026-19108: Use After Free in MZ Automation libiec61850
Description
A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The manipulation results in use after free. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 1.6.2 is sufficient to fix this issue. The patch is identified as 486fd57f3aed65bb9d636ff00f9ddce2e450b168. Upgrading the affected component is advised.
CVSS v4.0
Score 4.8medium
Affected software
pkg:github/mz-automation/libiec61850Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-19108 is a use-after-free vulnerability found in the deleteDataSetValuesShadowBuffer function of the src/iec61850/server/mms_mapping/reporting.c file in MZ Automation libiec61850 up to version 1.6.1. The vulnerability affects the URCB Revalidation component and requires local access with low privileges to exploit. Exploit code has been publicly disclosed. The vulnerability is addressed by upgrading to version 1.6.2, with the patch identified by commit 486fd57f3aed65bb9d636ff00f9ddce2e450b168.
Potential Impact
Successful exploitation can lead to limited confidentiality, integrity, and availability impacts due to use-after-free memory corruption. The attack requires local access and low privileges, reducing the overall risk. The CVSS 3.1 base score is 5.3 (low severity). No known active exploitation in the wild has been reported.
Mitigation Recommendations
Upgrade MZ Automation libiec61850 to version 1.6.2 or later to remediate this vulnerability. This official fix fully addresses the use-after-free issue. No additional mitigation steps are required beyond applying the patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-c2h4-j5j4-67wf
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-19108"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7573a2bf8831d539d92488
Added to database: 08/07/2026, 05:56:50 UTC
Last enriched: 08/07/2026, 08:27:07 UTC
Last updated: 09/22/2026, 01:54:35 UTC
Views: 100
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.