Junglewise Threat Intelligence

CVE-2026-81625: Greenbone OpenVAS stack buffer overflow in NASL test parsing

CVE-2026-81625 · Severity: high · CVSS 8.8 · Published 2026-08-27

Executive brief

Greenbone OpenVAS is a vulnerability scanning tool used by organizations to identify security issues in their networks and systems. A malicious or compromised NASL vulnerability test script can trigger a stack buffer overflow in the scanner engine, allowing an attacker with user privileges to gain complete control of the scanning system, compromising the integrity and availability of security operations and potentially exposing sensitive scan data.

Technical details

The vulnerability is a stack-based buffer overflow (CWE-121) in the NASL (Nessus Attack Scripting Language) test parsing engine of Greenbone OpenVAS. A malicious or compromised NASL vulnerability test script can trigger the overflow during execution on the scanner. Exploitation requires user-level privileges and a network connection to the scanner, but no additional user interaction. A successful exploit allows an attacker to achieve arbitrary code execution with full system access. Patches are available: Greenbone OS 25.0.6 (released 2026-08-06) and openvas-scanner v23.49.4 (released 2026-07-17).

Affected products

  • Greenbone Greenbone OS 5.0 to 25.0.5
  • Greenbone openvas-scanner 3.0 to 23.49.3

Timeline

  • 2026-08-27: disclosed: CVE-2026-81625 published
  • 2026-08-06: patched: Greenbone OS 25.0.6 released
  • 2026-07-17: patched: openvas-scanner v23.49.4 released
  • 2026-07-16: other: Vulnerability identified by Tristan Madani (Talence Security)

References