An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.
https://github.com/if-forget/CVE-2026-52134-libiec61850
https://github.com/mz-automation/libiec61850/tree/v1.6/src/goose/goose_receiver.c