Junglewise Threat Intelligence

CVE-2026-50039: MZ Automation libIEC61850 stack-based buffer overflow via Read Request

CVE-2026-50039 · Severity: high · CVSS 7.5 · Published 2026-07-23

Executive brief

MZ Automation libIEC61850 is a software library used in industrial control systems for communication in the energy, manufacturing, and transportation sectors. A security flaw has been identified that allows an attacker to send a specially crafted data request over the network to crash the service. This could lead to a loss of visibility or control over critical infrastructure equipment, potentially disrupting operations.

Technical details

A stack-based buffer overflow (CWE-121) exists in MZ Automation libIEC61850 versions 1.0.0 through 1.6.1. The vulnerability is triggered when the library processes a malformed MMS Read Request, leading to memory corruption. An unauthenticated remote attacker can exploit this over the network without user interaction to cause a denial-of-service (DoS) condition by crashing critical IEC 61850 services. While the primary impact is availability, such memory corruption vulnerabilities can sometimes be leveraged for broader system compromise depending on the environment. Users are advised to update to the latest build available on the vendor's GitHub repository.

Affected products

  • MZ Automation libIEC61850 v1.0.0 to v1.6.1

Timeline

  • 2026-07-23: disclosed: Initial publication of ICS Advisory ICSA-26-204-06
  • 2026-07-23: advisory: NVD published CVE-2026-50039 details

References

Related threats