CVE-2026-82619

Source
https://cve.org/CVERecord?id=CVE-2026-82619
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82619.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82619
Published
2026-08-31T05:15:10.327Z
Modified
2026-09-02T08:05:30.459292Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Systerel S2OPC subscription_mgr.c use after free
Details

A vulnerability was identified in Systerel S2OPC up to 1.7.3. The impacted element is the function monitoreditemeventfiltertreatment_bs__initeventfilterctxandresult of the file src/ClientServer/services/bgenc/subscriptionmgr.c. Such manipulation of the argument EventFilter leads to use after free. The attack may be performed from remote. The exploit is publicly available and might be used. The name of the patch is a4cee16a851b971be447a6ed531173702c722b99. It is best practice to apply a patch to resolve this issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82619.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-416"
    ]
}
References

Affected packages

Git / gitlab.com/systerel/S2OPC

Affected ranges

Type
GIT
Repo
https://gitlab.com/systerel/S2OPC
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "1.7.0"
        },
        {
            "last_affected": "1.7.0"
        },
        {
            "introduced": "1.7.1"
        },
        {
            "last_affected": "1.7.1"
        },
        {
            "introduced": "1.7.2"
        },
        {
            "last_affected": "1.7.2"
        },
        {
            "introduced": "1.7.3"
        },
        {
            "last_affected": "1.7.3"
        }
    ]
}

Affected versions

1.*
1.7.0
1.7.1
1.7.2
1.7.3

Database specific

vanir_signatures
[
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "327790412087619080217794881366560713090",
                "100739141495890847368128791996297141448",
                "171004637405442983094950572528549848238",
                "199045727184962237028180561182118460708",
                "287580903663288449745920717493563956695",
                "291619018550628469590750969514658740359",
                "23842524736949029098514706647918335105",
                "109415079199529168082368175377344693076",
                "56950556639377521260613460897897553715",
                "190655084495810621481023297372348122857",
                "164651956025664774217855073847577162349",
                "14337502840513584949415465804448975402"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-82619-28ce1924",
        "target": {
            "file": "src/ClientServer/services/bgenc/subscription_mgr.c"
        },
        "source": "https://gitlab.com/systerel/S2OPC@a4cee16a851b971be447a6ed531173702c722b99",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 712.0,
            "function_hash": "53500193491792638468462738531194967542"
        },
        "id": "CVE-2026-82619-b9e4efbd",
        "target": {
            "function": "subscription_mgr__fill_response_subscription_modify_monitored_items",
            "file": "src/ClientServer/services/bgenc/subscription_mgr.c"
        },
        "source": "https://gitlab.com/systerel/S2OPC@a4cee16a851b971be447a6ed531173702c722b99",
        "signature_version": "v1"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82619.json"
vanir_signatures_modified
"2026-09-02T08:05:30Z"