CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-9158

Critical · CVSS 9.8

Eclipse 4diac FORTE — Use-After-Free (CWE-416)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-416

Description

In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).

Search profile — drives PoC discovery

Symbols DELETEmanagement interfacedangling pointerfreed memoryconnection command
Keywords CVE-2026-91584diac FORTEuse-after-freeDELETE connectionmanagement interfacedangling pointerEclipse 4diac
Versions: 3.0.0 to 3.1.0

References

Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z