---
id: CVE-2026-103432
title: >-
  apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in
  getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and
  upsfstats.cgi), a related issue to CVE-2026-15544.
summary: >-
  apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in
  getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and
  upsfstats.cgi), a related issue to CVE-2026-15544.
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-121
vendor: apcupsd
product: apcupsd
affected:
  - apcupsd <= 3.14.14
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:17:31.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103432'
references:
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2493140'
    label: cve@mitre.org
  - url: >-
      https://github.com/therealbstern/apcupsd/blob/224d19d5faa508d04267f6135fe53d50800550de/src/cgi/upsfetch.c#L240
    label: cve@mitre.org
  - url: 'https://sourceforge.net/projects/apcupsd/'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-30T19:35:14.295763Z'
ingestedAt: '2026-09-30T16:10:07.783Z'
---

## Overview

apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
