Impact
NI LabVIEW contains an out‑of‑bounds write that can corrupt memory. An attacker can craft a VI file that, when opened by a user, triggers the corruption. This may lead to disclosure of sensitive data or execution of arbitrary code, impacting the confidentiality and integrity of the system.
Affected Systems
The vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and all earlier releases. Systems running any of these versions are potentially vulnerable until a patch or newer version is applied.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, but the EPSS score is not available, so widespread exploitation probability is unclear. The vulnerability is currently not listed in the CISA KEV catalog. Attack requires a user to open a malicious VI file, so the attack vector is local user interaction. Exploitation would require the attacker to supply or convince a user to load a crafted VI onto the target system.
OpenCVE Enrichment