CVE-2026-26008

7.5

EVerest · everest-core

EVerest EV charging software contains an out-of-bounds read vulnerability in versions prior to 2026.02.0, which can lead to a remote crash or memory corruption via network-based CSMS messages.

Executive summary

A critical vulnerability in the EVerest everest-core software stack allows unauthenticated remote attackers to cause a service crash or memory corruption.

Vulnerability

This flaw is an out-of-bounds read (CWE-125) triggered when the CSMS sends an UpdateAllowedEnergyTransferModes command over the network. The vulnerability is exploitable by an unauthenticated attacker, as the software fails to properly validate inputs during the energy transfer mode update process.

Business impact

The potential for a remote crash poses a significant risk to the availability of EV charging infrastructure. Given the CVSS score of 7.5, this high-severity vulnerability could lead to widespread service disruption, requiring manual intervention or system reboots to restore operations, which may impact business continuity for operators relying on the EVerest stack.

Remediation

Immediate Action: Update the EVerest everest-core software to version 2026.2.0 or later to apply the security patch.

Proactive Monitoring: Monitor network traffic for malformed or suspicious UpdateAllowedEnergyTransferModes packets and audit system logs for unexpected service restarts or segmentation faults.

Compensating Controls: Implement network segmentation to restrict access to the CSMS interface to trusted sources only, and utilize intrusion detection systems to identify anomalous communication patterns.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The vulnerability represents a significant availability risk to EV charging systems. Organizations deploying the EVerest stack must prioritize the transition to version 2026.2.0 to eliminate the out-of-bounds read condition. Failure to patch may result in intermittent or total loss of service due to remote exploitation.

More EVerest CVEs

Sources