---
id: CVE-2026-15105
title: A flaw has been found in davenardella snap7 up to 1.4.3
summary: >-
  A flaw has been found in davenardella snap7 up to 1.4.3. This affects the
  function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp of
  the component ReadVar Request Handler. This manipulation causes out-of-bounds
  write. …
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-119
  - CWE-787
published: '2026-07-08'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15105'
references:
  - url: 'https://github.com/davenardella/snap7/'
    label: cna@vuldb.com
  - url: 'https://github.com/davenardella/snap7/issues/16'
    label: cna@vuldb.com
  - url: 'https://github.com/user-attachments/files/28681740/poc.zip'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-15105'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/851026'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/376946'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/376946/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00377
epssPercentile: 0.28988
ingestedAt: '2026-08-01T16:13:07.979Z'
---

## Overview

A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp of the component ReadVar Request Handler. This manipulation causes out-of-bounds write. The attack requires access to the local network. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
