---
id: CVE-2026-19108
title: A vulnerability was found in MZ Automation libiec61850 up to 1.6.1
summary: >-
  A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The
  affected element is the function deleteDataSetValuesShadowBuffer of the file
  src/iec61850/server/mms_mapping/reporting.c of the component URCB
  Revalidation. The mani…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-119
  - CWE-416
published: '2026-08-06'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19108'
references:
  - url: >-
      https://github.com/mz-automation/libiec61850/commit/486fd57f3aed65bb9d636ff00f9ddce2e450b168
    label: cna@vuldb.com
  - url: 'https://github.com/mz-automation/libiec61850/issues/596'
    label: cna@vuldb.com
  - url: 'https://github.com/mz-automation/libiec61850/releases/tag/v1.6.2'
    label: cna@vuldb.com
  - url: 'https://github.com/user-attachments/files/29163236/POC.zip'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-19108'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/864520'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/386569'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/386569/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00159
epssPercentile: 0.0426
ingestedAt: '2026-08-08T21:30:13.891Z'
---

## Overview

A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The manipulation results in use after free. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 1.6.2 is sufficient to fix this issue. The patch is identified as 486fd57f3aed65bb9d636ff00f9ddce2e450b168. Upgrading the affected component is advised.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
