Description
Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6, from 6.1.2.21 before 6.1.*.
Published: 2026-09-22
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Out-of-bounds read capable of overreading buffers and potentially leaking confidential data.
Action: Apply Patch
AI Analysis

Impact

An out-of-bounds read, incorrect function argument count, and type confusion in the core libraries allow an attacker to overread interior buffers. The CVE groups these weaknesses under CWE‑125, CWE‑685, and CWE‑843. A successful exploit could expose memory contents beyond the intended buffer, leading to information disclosure or service destabilization from data corruption.

Affected Systems

RTI Connext Professional Core Libraries, specifically versions 7.4.0 prior to 7.7.0.1, 7.3.0 prior to 7.3.1.6, and 6.1.2.21 prior to 6.1.*. Systems running any of these releases are vulnerable.

Risk and Exploitability

The CVSS score of 6.8 indicates a serious but not critical impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network-based, requiring the attacker to communicate with the Connext services; local exploitation may also be feasible for processes running with elevated privileges. Because the flaw reads uncontrolled memory, an attacker could gain sensitive data or cause a crash, depending on how the buffer is treated. No immediate exploits are publicly known, but the lack of a KEV listing does not rule out later exploitation.

Generated by OpenCVE AI on September 22, 2026 at 19:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RTI Connext Professional to a non‑affected version—greater than 7.7.0.1 for the 7.x line and greater than 7.3.1.6 for the 7.3 line, and any release newer than 6.1.* for the 6.x line.
  • If an upgrade is not immediately possible, isolate the Connext services by restricting inbound connections to trusted hosts using firewalls or ACLs, thereby limiting exposure to potential attackers.
  • Enable or enforce runtime memory safety mechanisms such as address‑sanitizer or bounds checking tools to detect and mitigate out‑of‑bounds reads during development and testing.

Generated by OpenCVE AI on September 22, 2026 at 19:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6, from 6.1.2.21 before 6.1.*.
Title Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.
First Time appeared Rti
Rti connext Professional
Weaknesses CWE-125
CWE-685
CWE-843
CPEs cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
Vendors & Products Rti
Rti connext Professional
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rti Connext Professional
cve-icon MITRE

Status: PUBLISHED

Assigner: RTI

Published:

Updated: 2026-09-22T18:48:29.246Z

Reserved: 2026-07-31T07:29:34.430Z

Link: CVE-2026-18458

cve-icon Vulnrichment

Updated: 2026-09-22T18:48:25.420Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:11.640

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-18458

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:15:09Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-685

    Function Call With Incorrect Number of Arguments

  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')