CVE-2026-26008 is a high-severity vulnerability (CVSS 7.5) affecting the EVerest EV charging software stack, specifically versions prior to 2026.02.0, which has been patched in version 2026.2.0. This out-of-bounds access (std::vector) can be triggered remotely over the network with low complexity and no user interaction, potentially leading to a system crash or memory corruption. The primary impact is on system availability, as no confidentiality or integrity impacts have been identified. Currently, there is no evidence of active exploitation, nor are public exploit modules available, although the vulnerability has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.02.0CPE matchmatch criteria | cpe:2.3:o:linuxfoundation:everest:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.