rpm_decode_object_id of the file src/bacnet/rpm.c of the component ReadPropertyMultiple Service. The manipulation results in out-of-bounds read.This vulnerability is reported as CVE-2026-41502. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.