CVE-2026-41475 | bacnet-stack BACnet Stack up to 1.4.2 WritePropertyMultiple Service wpm_decode_object_property out-of-bounds (GHSA-cvv4-v3g6-4jmv / EUVD-2026-25621)
A vulnerability classified as problematic has been found in bacnet-stack BACnet Stack up to 1.4.2. This issue affects the function wpm_decode_object_property of the component WritePropertyMultiple Service. The manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-41475. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.