{"id":"CVE-2026-9158","title":"In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer","summary":"In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416"],"vendor":"eclipse","product":"4diac_forte","affected":["4diac_forte >= 3.0.0, <= 3.1.0"],"published":"2026-06-18","updated":"2026-07-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9158","references":[{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/109","label":"emo@eclipse.org"}],"tags":["nvd"],"epss":0.00601,"epssPercentile":0.47454,"ingestedAt":"2026-07-03T13:02:27.804Z","slug":"CVE-2026-9158","body":"## Overview\n\nIn Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).\n\n## Affected\n\n- `4diac_forte >= 3.0.0, <= 3.1.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}