# CVE-2026-50103

## Summary

- **CVE ID:** CVE-2026-50103
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-228
- **Published:** Jul 23, 2026
- **Last Modified:** Jul 24, 2026

## Description

A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.

## Affected Products

- MZ Automation — libIEC61850 (1.0.0)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 18.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._