CVE Watchtower

← Back to CVE List

CVE-2026-90782NVD

Description

S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate.
Severity Level
MEDIUM (5.3)
Published Date
13/09/2026
Last Modified
13/09/2026
Exploitation Status
????
EPSS Score
0.32% (percentile 25.2%)

CVSS Base Metrics

CVSS v3 (3.1)
MEDIUM 5.3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4 (4.0)
MEDIUM 6
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Weaknesses (CWE)

CWE-476 - NULL Pointer Dereference

Affected & Patched Versions

ProductAffected VersionsPatched Version
Systerel S2OPC0 - <= 1.7.38848f051eed069b107ae7cb16a346d6f6386a8f5
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.