---
id: CVE-2026-18582
title: A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1
summary: >-
  A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1.
  This vulnerability affects the function Reporting_RCBWriteAccessHandler of the
  file src/iec61850/server/mms_mapping/reporting.c of the component Report
  Sending…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-590
published: '2026-08-03'
updated: '2026-08-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18582'
references:
  - url: 'https://github.com/gff-cw/information/issues/2'
    label: cna@vuldb.com
  - url: 'https://github.com/mz-automation/libiec61850/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/mz-automation/libiec61850/commit/5b2a69f44256b8548927d8afdd7ac5f5381abe1e
    label: cna@vuldb.com
  - url: 'https://github.com/mz-automation/libiec61850/releases/tag/v1.6.2'
    label: cna@vuldb.com
  - url: >-
      https://github.com/mz-automation/libiec61850/security/advisories/GHSA-7qg8-hm25-rv5v
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-18582'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/844920'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/385411'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/385411/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-08-03T02:22:11.362Z'
epss: 0.00859
epssPercentile: 0.56729
---

## Overview

A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Reporting_RCBWriteAccessHandler of the file src/iec61850/server/mms_mapping/reporting.c of the component Report Sending Path Handler. The manipulation results in free of memory not on the heap. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.2 is able to resolve this issue. The patch is identified as 5b2a69f44256b8548927d8afdd7ac5f5381abe1e. It is suggested to upgrade the affected component. The vendor was contacted early about this disclosure.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
