A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. It has been declared as critical. The affected element is the function MmsMapping_varAccessSpecToObjectReference of the file src/iec61850/common/iec61850_common.c of the component MMS Protocol Workflow. Such manipulation of the argument GetNamedVariableListAttributesResponse.itemId leads to heap-based buffer overflow.

This vulnerability is listed as CVE-2026-19259. The attack must be carried out locally. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.