There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q3 and prior versions. | |
| Title | Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI LabVIEW | |
| First Time appeared |
Ni
Ni labview |
|
| Weaknesses | CWE-195 | |
| CPEs | cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ni
Ni labview |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: NI
Published: 2026-08-25T16:09:03.396Z
Updated: 2026-08-26T03:56:26.366Z
Reserved: 2026-07-30T22:06:03.338Z
Link: CVE-2026-18444
Updated: 2026-08-25T19:42:47.043Z
Status : Awaiting Analysis
Published: 2026-08-25T17:17:05.803
Modified: 2026-08-28T21:16:15.740
Link: CVE-2026-18444
No data.