What is CVE-2026-52134?
CVE-2026-52134 is a vulnerability in the libiec61850 library (v1.6) where the `parseGoosePayload()` function fails to properly handle authentication, allowing attackers to bypass it using a captured GOOSE frame. This primarily affects SCADA systems relying on IEC 61850 protocols, such as electrical substations, and mitigation requires updating the library or applying vendor patches.
Azərbaycanca: CVE-2026-52134 libiec61850 kitabxanasında (v1.6) aşkarlanan kritik boşluqdur. Bu qüsur, `parseGoosePayload()` funksiyasındakı problem səbəbindən, təcavüzkara tutulmuş bir GOOSE frame vasitəsilə autentifikasiyanı keçməyə imkan yaradır. Bu, xüsusilə elektrik yarımstansiyaları kimi IEC 61850 protokolu istifadə edən SCADA sistemlərinə təsir edir; dərhal kitabxananı yeniləmək və ya müvafiq yamaq tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which component is affected by CVE-2026-52134?
This vulnerability affects the `parseGoosePayload()` function in version 1.6 of the libiec61850 library.
What type of environments are at risk from this flaw?
The flaw primarily poses a risk to SCADA systems using the IEC 61850 protocol, such as electrical substations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.