CVE-2026-82618: Systerel s2opc

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability was determined in Systerel S2OPC up to 1.7.3. The affected element is the function set_range_matrix_on_string_array of the file src/Common/opcua_types/sopc_builtintypes.c of the component String Array Range Writing. This manipulation causes out-of-bounds read. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

  • Systerel s2opc: version 1.7.0 only; version 1.7.1 only; version 1.7.2 only; version 1.7.3 only

Published 2026-08-31. Last modified 2026-08-31.