A vulnerability, which was classified as critical, has been found in o6 open62541 up to 1.5.5. This issue affects the function
UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is known as CVE-2026-18784. Attacking locally is a requirement. Furthermore, an exploit is available.
The project closed the issue report, stating that this is not the official way to report a security vulnerability.