Description
There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI file.  This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.
Published: 2026-08-25
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow flaw in NI LabVIEW causes an out‑of‑bounds write when processing a specially crafted VI file. The overflow can lead to information disclosure or arbitrary code execution, as specified by CWE‑190.

Affected Systems

NI LabVIEW 2026 Q3 and all earlier releases are affected.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. EPSS data is unavailable and the vulnerability is not listed in CISA KEV, suggesting it is not known to be actively exploited in the wild. Exploitation requires an attacker to persuade a user to open a malicious VI file, implying a local or social‑engineering attack vector rather than a remote network attack.

Generated by OpenCVE AI on August 25, 2026 at 18:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update NI LabVIEW to the latest release that contains the fix for the integer‑overflow flaw; the update is documented in the NI security advisory.
  • Follow the guidance in the advisory to configure LabVIEW to reject or quarantine new or unknown VI files until the update is installed.
  • If an immediate update is not possible, restrict user access to external VI files and prohibit opening of untrusted files until the fix is applied.

Generated by OpenCVE AI on August 25, 2026 at 18:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI file.  This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.
Title Integer Overflow Vulnerability Resulting in an Out of Bounds Write in NI LabVIEW
First Time appeared Ni
Ni labview
Weaknesses CWE-190
CPEs cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:*
Vendors & Products Ni
Ni labview
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-08-25T16:15:27.915Z

Reserved: 2026-07-30T22:06:04.014Z

Link: CVE-2026-18445

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T17:17:06.093

Modified: 2026-08-25T17:17:06.093

Link: CVE-2026-18445

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T18:15:04Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound