Impact
An integer overflow flaw in NI LabVIEW causes an out‑of‑bounds write when processing a specially crafted VI file. The overflow can lead to information disclosure or arbitrary code execution, as specified by CWE‑190.
Affected Systems
NI LabVIEW 2026 Q3 and all earlier releases are affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS data is unavailable and the vulnerability is not listed in CISA KEV, suggesting it is not known to be actively exploited in the wild. Exploitation requires an attacker to persuade a user to open a malicious VI file, implying a local or social‑engineering attack vector rather than a remote network attack.
OpenCVE Enrichment