CVE-2026-63035

Published: Lug 31, 2026 Last Modified: Lug 31, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,2
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 8,1
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: high
Availability: high

Description

AI Translation Available

A heap use-after-free vulnerability in the TransferSubscriptions service
in open62541 may allow an authenticated attacker to cause a denial of
service or potentially execute arbitrary code.

416

Use After Free

Stable
Common Consequences
Security Scopes Affected:
Integrity Availability Confidentiality
Potential Impacts:
Modify Memory Dos: Crash, Exit, Or Restart Read Memory Execute Unauthorized Code Or Commands
Applicable Platforms
Languages: Memory-Unsafe, C, C++
View CWE Details
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-2…
https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4…
https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf060…
https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8…
https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb…
https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08
https://www.o6-automation.com/contact