CVE-2026-21878Disclosure(bacnetstack / bacnet_stack)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability has been discovered in BACnet Stack's file writing functionality where there is no validation of user-provided file paths, allowing attackers to write files to arbitrary directories. This affects apps/readfile/main.c and ports/posix/bacfile-posix.c. This vulnerability is fixed in 1.5.0.rc3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bacnet_stack

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-13); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
bacnet_stack

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-13: 2Mentions · 2026-02-18: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-18: 102-1302-18
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-132
Disclosure2
2026-02-181
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-21878 BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability has been discovered in BACnet Stack's file wri… https://www.cve.org/CVERecord?id=CVE-2026-21878

    Post summary

    The text announces a newly discovered vulnerability in BACnet Stack before version 1.5.0.rc3, but provides no technical details, exploit information, or mitigation guidance.

    00020438
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-21878 BACnet Stack Directory Traversal Vulnerability Allows Arbitrary File Writing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21878

    Post summary

    A newly disclosed directory traversal flaw in the BACnet Stack permits arbitrary file writes, as noted in the Vulmon vulnerability entry.

    0001026
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-21878 (CVSS:7.5, HIGH) is Awaiting Analysis. BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability ..https://nvd.nist.gov/vuln/detail/CVE-2026-21878 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-21878, a high severity flaw in BACnet Stack versions before 1.5.0.rc3, is currently awaiting analysis with no PoC, exploit, or patch announced.

    0000036
    171 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appbacnetstackbacnet_stack1.5.0--
Appbacnetstackbacnet_stack1.5.0--

Explore more