---
id: CVE-2026-103436
title: >-
  apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in
  src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi
summary: >-
  apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in
  src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On
  the single-field path, when the matched STATUS line has fewer than three
  whitesp…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-457
vendor: apcupsd
product: apcupsd
affected:
  - apcupsd <= 3.14.14
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T17:32:07.107'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103436'
references:
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2493140'
    label: cve@mitre.org
  - url: >-
      https://github.com/therealbstern/apcupsd/blob/224d19d5faa508d04267f6135fe53d50800550de/src/cgi/upsfetch.c#L240
    label: cve@mitre.org
  - url: 'https://sourceforge.net/projects/apcupsd/'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T16:10:07.784Z'
---

## Overview

apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three whitespace-separated tokens, sscanf("%*s %*s %s", answer) performs no assignment but the function returns success, and thus the caller prints the uninitialized destination buffer into the HTTP response.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
