Junglewise Threat Intelligence

CVE-2026-9158: Eclipse 4diac FORTE use-after-free in CResource::deleteConnection

CVE-2026-9158 · Severity: info · CVSS 5.2 · Published 2026-06-18

Vendors: Eclipse Foundation.

Executive brief

Eclipse 4diac FORTE is a runtime environment for industrial automation and control systems. A security flaw in its management interface allows an attacker to send a malicious command that corrupts the system's memory. This can lead to system instability, unauthorized data modification, or a complete shutdown of the industrial control processes.

Technical details

A use-after-free vulnerability exists in the CResource::deleteConnection component of Eclipse 4diac FORTE. The flaw is triggered when a specially crafted DELETE connection command is sent to the management interface, resulting in a dangling pointer. Subsequent commands can then access this freed memory. An attacker with access to the adjacent network can exploit this to achieve arbitrary code execution or cause a denial-of-service (DoS) condition. A fix has been proposed in the project's repository via pull request 883.

Affected products

  • Eclipse Foundation 4diac FORTE 3.0.0 to 3.1.0

Timeline

  • 2026-06-18: advisory: NVD and Eclipse Foundation published the advisory

References