CVE-2026-26264 – BACnet Stack WriteProperty decoding length underflow leads to OOB read and crash
CVE ID : CVE-2026-26264
Published : Feb. 13, 2026, 7:17 p.m. | 1 hour, 12 minutes ago
Description : BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0rc4 and 1.4.3rc2, a malformed WriteProperty request can trigger a length underflow in the BACnet stack, leading to an out‑of‑bounds read and a crash (DoS). The issue is in wp.c within wp_decode_service_request. When decoding the optional priority context tag, the code passes apdu_len – apdu_size to bacnet_unsigned_context_decode without validating that apdu_size
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…