What is CVE-2026-19259?
A critical vulnerability exists in MZ Automation libiec61850 up to version 1.6.1, specifically in the `MmsMapping_varAccessSpecToObjectReference` function within the MMS protocol workflow. Manipulation of the `GetNamedVariableListAttr` argument could allow for remote code execution, potentially impacting SCADA and power grid systems utilizing the IEC 61850 standard. Immediate update to version 1.6.2 or later is recommended.
Azərbaycanca: MZ Automation libiec61850 kitabxanasının 1.6.1 versiyasına qədər olan versiyalarında MMS protokolu iş axınında `MmsMapping_varAccessSpecToObjectReference` funksiyasında kritik bir boşluq aşkar edilib. `GetNamedVariableListAttr` arqumenti üzərindən həyata keçirilən manipulyasiya, uzaqdan kod icrasına imkan verə bilər, bu da IEC 61850 standartından istifadə edən SCADA və elektrik şəbəkəsi sistemlərini təhlükə altına qoyur. Dərhal 1.6.2 və ya daha yuxarı versiyaya yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which library and versions are affected by CVE-2026-19259?
CVE-2026-19259 affects MZ Automation libiec61850 library up to version 1.6.1. An immediate update to version 1.6.2 or later is recommended to address this vulnerability.
What type of attack can be performed by exploiting CVE-2026-19259?
This critical vulnerability can allow remote code execution (RCE) by manipulating the `GetNamedVariableListAttr` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.