Impact
NI LabVIEW 2026 Q3 and earlier editions contain an integer conversion flaw that triggers an out‑of‑bounds read when a malicious image is loaded from a specially crafted VI file. This flaw, classified as CWE‑195, enables an attacker to read memory beyond intended bounds, which may expose sensitive data or allow arbitrary code execution within the current user session.
Affected Systems
The affected product is National Instruments LabVIEW, specifically version 2026 Q3 and all prior releases. Users operating LabVIEW on any platform supported by NI should verify their build against the vendor advisory to determine whether the installation remains vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. Exploitation requires user interaction, namely opening a malicious VI file crafted by the attacker. While EPSS data is not available, the absence of a known public exploit and the lack of inclusion in the CISA KEV catalog reduce the immediate widespread risk, yet the potential for code execution and information disclosure warrants prompt remediation.
OpenCVE Enrichment