Description
There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI file.  This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.
Published: 2026-08-25
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

NI LabVIEW 2026 Q3 and earlier editions contain an integer conversion flaw that triggers an out‑of‑bounds read when a malicious image is loaded from a specially crafted VI file. This flaw, classified as CWE‑195, enables an attacker to read memory beyond intended bounds, which may expose sensitive data or allow arbitrary code execution within the current user session.

Affected Systems

The affected product is National Instruments LabVIEW, specifically version 2026 Q3 and all prior releases. Users operating LabVIEW on any platform supported by NI should verify their build against the vendor advisory to determine whether the installation remains vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity. Exploitation requires user interaction, namely opening a malicious VI file crafted by the attacker. While EPSS data is not available, the absence of a known public exploit and the lack of inclusion in the CISA KEV catalog reduce the immediate widespread risk, yet the potential for code execution and information disclosure warrants prompt remediation.

Generated by OpenCVE AI on August 25, 2026 at 21:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest LabVIEW patch released by NI for version 2026 Q3 or later, or update to the newest available release.
  • Enforce a strict policy that prevents users from opening VI files from untrusted or unknown sources; require scanning or digital signature verification before execution.
  • Run LabVIEW under least privilege and consider confining the application to a sandbox or virtualized environment to limit the impact of a successful exploit.

Generated by OpenCVE AI on August 25, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ni:labview:2023:q1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch4:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch5:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch6:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch7:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch8:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch9:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:-:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q1_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch4:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch5:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch6:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q1_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q1_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q1_patch3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3_patch3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3_patch4:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2026:q1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2026:q1_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2026:q1_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2026:q3:*:*:*:*:*:*

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI file.  This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.
Title Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI LabVIEW
First Time appeared Ni
Ni labview
Weaknesses CWE-195
CPEs cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:*
Vendors & Products Ni
Ni labview
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-08-31T15:15:06.186Z

Reserved: 2026-07-30T22:06:03.338Z

Link: CVE-2026-18444

cve-icon Vulnrichment

Updated: 2026-08-25T19:42:47.043Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T17:17:05.803

Modified: 2026-09-08T14:30:51.530

Link: CVE-2026-18444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:15:13Z

Weaknesses
  • CWE-195

    Signed to Unsigned Conversion Error