CVE-2026-41503 | bacnet-stack BACnet Stack up to 1.4.2 ReadPropertyMultiple Service src/bacnet/rpm.c rpm_decode_object_property out-of-bounds (GHSA-5w2v-mwqj-pr2c / EUVD-2026-25625)
A vulnerability, which was classified as problematic, has been found in bacnet-stack BACnet Stack up to 1.4.2. The affected element is the function rpm_decode_object_property of the file src/bacnet/rpm.c of the component ReadPropertyMultiple Service. This manipulation causes out-of-bounds read.
This vulnerability appears as CVE-2026-41503. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.