CVE-2026-103436: Apcupsd
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three whitespace-separated tokens, sscanf("%*s %*s %s", answer) performs no assignment but the function returns success, and thus the caller prints the uninitialized destination buffer into the HTTP response.
Affected products
- Apcupsd Apcupsd: up to and including 3.14.14
Published 2026-09-30. Last modified 2026-10-02.