RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1.
{
"cna_assigner": "cisa-cg",
"cwe_ids": [
"CWE-863"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82358.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82358.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "325124189572272260870311175552757248080",
"length": 1636
},
"id": "CVE-2026-82358-14019273",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
"target": {
"file": "src/co_sdo_server.c",
"function": "co_sdo_rx_download_seg_req"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "272461627778368712007747684045902712041",
"length": 245
},
"id": "CVE-2026-82358-2040c33c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
"target": {
"file": "src/co_lss.c",
"function": "co_lss_identity_get"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "42002365070947738037223220353581527221",
"length": 162
},
"id": "CVE-2026-82358-320284ea",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
"target": {
"file": "src/co_lss.c",
"function": "co_lss_init"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"164147392278730642748241061479189970780",
"203878713004402079833562706097211232962",
"36616733524128164312750524750112391345",
"184011724265028255398845821010442293599"
],
"threshold": 0.9
},
"id": "CVE-2026-82358-5912d75d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
"target": {
"file": "samples/slave/slave.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"106088642351237489842622141963085583595",
"294804620323865334729115160754181465791",
"177164280203892796323396481439412612271",
"248326608781997156811507574462112270840"
],
"threshold": 0.9
},
"id": "CVE-2026-82358-6293b1e4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
"target": {
"file": "test/test_util.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "314924377624210806205440908866671679246",
"length": 607
},
"id": "CVE-2026-82358-6b0c2a0b",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
"target": {
"file": "src/co_lss.c",
"function": "co_lss_inquire_identity"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"266816321767689576519285662459928189713",
"49362068846328814605457804122061796961",
"287929551429695583010339431912881230300",
"288850488669783553292776483383664877510",
"63879643187827220328974635430171677939",
"287929551429695583010339431912881230300"
],
"threshold": 0.9
},
"id": "CVE-2026-82358-8e27e279",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
"target": {
"file": "src/co_sdo_server.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"243395724250237381427400046914416141459",
"31433916477770798747325588839471215715",
"257976297618390070030383337467454463079",
"5242711043273888949991228422928685265",
"90606467274305947059523405210967921996",
"54844704610018267246297714523900539764",
"147907157503994625138699193841728505049",
"282477856285567365402150966133659714617",
"332114166126657880949033532728448139205",
"81815288020120805035736635117768597116",
"219713907162302157231759612504008743719",
"184891408626408031480477908573546665840",
"48305270904910213964220257716210185667",
"126525271293956646260090723958688731102",
"336000195125429997682413119524712933449",
"271240154073052200330035903826402909877",
"176942762728670528751948003093638828292",
"71375677890224760355768708580792307787",
"81828347601982261933991283728757467542",
"145285214347586748090034768455699017615",
"280356284118779465758669038031113813348",
"148515975041281695072210762710485509763",
"174378154041941140982802537899033326660",
"57823921473444506236460946385675493925",
"197766511101439003124718431997910841005",
"143770263343649922180970817138061590923",
"311656363305188815492257137614791189754"
],
"threshold": 0.9
},
"id": "CVE-2026-82358-8f9dccb9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
"target": {
"file": "src/co_lss.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"243939391360276321077839900214661758168",
"161633625510567069405448303105720623849",
"34971806247636875429451207495255617917"
],
"threshold": 0.9
},
"id": "CVE-2026-82358-92f9b92f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
"target": {
"file": "test/test_sdo_server.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "331741183972024165610337617313325074997",
"length": 1067
},
"id": "CVE-2026-82358-bb8f60c9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
"target": {
"file": "src/co_sdo_server.c",
"function": "co_sdo_rx_upload_seg_req"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "190295048243472633345103552246730765234",
"length": 910
},
"id": "CVE-2026-82358-fc75be17",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
"target": {
"file": "samples/slave/slave.c",
"function": "slave_init"
}
}
]
"2026-10-03T08:05:11Z"