Description
Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.1.0 before 7.3.1.6.
Published: 2026-09-22
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: File manipulation via double free
Action: Apply Patch
AI Analysis

Impact

A double free bug in the core libraries of RTI Connext Professional permits an attacker who can trigger the fault to manipulate files arbitrarily. The flaw is classified as CWE-415, a classic example of improper memory deallocation that can corrupt program state or overwrite critical data structures. While no remote code execution is advertised, the ability to rewrite files undermines the integrity of the application and could be leveraged to subvert configuration or workaround controls.

Affected Systems

The vulnerability affects RTI Connext Professional (Core Libraries) from version 7.4.0 up to but not including 7.7.0.1, and from 7.1.0 up to but not including 7.3.1.6. Any deployment using these releases is potentially impacted.

Risk and Exploitability

With a CVSS score of 6.9, the flaw presents a moderate severity assessment. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation to date. The likely attack vector is local or network via an application that communicates with the Connext middleware, with the attacker needing to exercise a specific sequence that causes the double free. Because the flaw can modify file contents, its exploitation could be strategic and subtle rather than immediate.

Generated by OpenCVE AI on September 22, 2026 at 19:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RTI Connext Professional to a fixed version—at least 7.7.0.1 or 7.3.1.6 or later.
  • Apply any vendor‑supplied patch that addresses the double‑free flaw if the upgrade path is not immediately available.
  • Restrict file permissions for the RTI Connext files and running processes so that a file alteration does not compromise critical system configuration or data.

Generated by OpenCVE AI on September 22, 2026 at 19:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.1.0 before 7.3.1.6.
Title Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation.
First Time appeared Rti
Rti connext Professional
Weaknesses CWE-415
CPEs cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
Vendors & Products Rti
Rti connext Professional
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rti Connext Professional
cve-icon MITRE

Status: PUBLISHED

Assigner: RTI

Published:

Updated: 2026-09-22T18:59:02.971Z

Reserved: 2026-06-05T15:42:26.908Z

Link: CVE-2026-11388

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:10.520

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-11388

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:45:06Z

Weaknesses