A vulnerability was found in Systerel S2OPC up to 1.7.3. It has been classified as problematic. This affects the function
LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/frontend/client_wrapper/internal/state_machine.c of the component DeleteMonitoredItemsRequest Handler. This manipulation causes out-of-bounds read.
The identification of this vulnerability is CVE-2026-18790. The attack can only be executed locally. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.