CVE-2026-63559
o6 Automation open62541 Integer Overflow or Wraparound
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.
| CWE | CWE-190 |
| Vendor | o6 automation |
| Product | open62541 |
| Published | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for o6 automation open62541
Be the first to know when new high vulnerabilities affecting o6 automation open62541 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
o6 Automation / open62541
1.3.0 โค 1.3.17 1.4.0 โค 1.4.16 1.5.0 โค 1.5.4 master
References
o6-automation.com: https://www.o6-automation.com/contact github.com: https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f github.com: https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60 github.com: https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e github.com: https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df cisa.gov: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08 github.com: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-08.json
Credits
Asher Davila of Palo Alto Networks reported this vulnerability to CISA.