---
id: CVE-2026-90572
title: A vulnerability was determined in davenardella snap7 up to 1.4.3
summary: >-
  A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected
  element is the function TSnap7MicroClient::opUpload of the file
  src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen
  can lead to mem…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-119
vendor: davenardella
product: snap7
affected:
  - snap7 1.4.0
  - snap7 1.4.1
  - snap7 1.4.2
  - snap7 1.4.3
published: '2026-09-13'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T15:17:28.670'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90572'
references:
  - url: 'https://github.com/davenardella/snap7/'
    label: cna@vuldb.com
  - url: 'https://github.com/davenardella/snap7/issues/30'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90572'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/912711'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403157'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403157/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.004
epssPercentile: 0.34102
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T13:50:42.914558Z'
ingestedAt: '2026-09-14T15:23:07.469Z'
---

## Overview

A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to memory corruption. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
