Impact
NI LabVIEW 2026 Q3 and earlier versions contain an integer conversion flaw that causes an out‑of‑bounds read when loading specially crafted images. The vulnerability can lead to disclosure of sensitive data or, in worst‑case scenarios, arbitrary code execution within the user’s session. The flaw is tied to CWE‑195, an improper conversion or truncation of an integral type.
Affected Systems
The affected product is National Instruments LabVIEW, specifically version 2026 Q3 and all earlier releases. Users running LabVIEW on any platform supported by NI should verify their current LabVIEW build against the version list in the vendor advisory for potential impact.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. Exploitation requires a user to open a malicious VI file, implying a user interaction attack vector. Exploit probability data from EPSS is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Given the potential for code execution and lack of mitigation in older releases, the risk remains significant for systems that continue to operate affected versions or accept unknown VI files.
OpenCVE Enrichment