CVE-2026-27816 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 handle_update_energy_transfer_modes out-of-bounds write (GHSA-gq54-j8f4-xj8c / EUVD-2026-16226)
A vulnerability categorized as critical has been discovered in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0. This issue affects the function ISO15118_chargerImpl::handle_update_energy_transfer_modes. The manipulation results in out-of-bounds write.
This vulnerability is identified as CVE-2026-27816. The attack is only possible with local access. There is not any exploit available.
It is advisable to upgrade the affected component.