CVE-2026-9158
Critical · CVSS 9.8Eclipse 4diac FORTE — Use-After-Free (CWE-416)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-416
Description
In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).
Search profile — drives PoC discovery
Symbols DELETEmanagement interfacedangling pointerfreed memoryconnection command
Keywords CVE-2026-91584diac FORTEuse-after-freeDELETE connectionmanagement interfacedangling pointerEclipse 4diac
Versions: 3.0.0 to 3.1.0
References
Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z