CVE-2026-63035 Details
Description
A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.
A heap use-after-free vulnerability has been identified in the TransferSubscriptions service of o6 Automation open62541. This vulnerability may allow an authenticated attacker to cause a denial-of-service or potentially execute arbitrary code. The issue arises because the TransferSubscriptions service does not properly manage memory when transferring subscription data, leading to the possibility of accessing freed memory.
o6 Automation has prepared mitigations and fixes for this vulnerability. Users are advised to update to the latest version. The new version can be obtained by contacting o6 Automation or by downloading from their website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |