Description
Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.1x before 5.1.*.
Published: 2026-09-22
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Abuse of existing functionality caused by an incorrect calculation in core libraries
Action: Patch immediately
AI Analysis

Impact

The vulnerability is governed by CWE‑682 and arises from an incorrect calculation within RTI Connext Professional’s core libraries. This flaw permits an attacker to abuse the software’s existing functionality, potentially causing unintended behaviour, system misconfiguration, or denial of service. The specific damage depends on how the calculation is used in the application but the flaw fundamentally undermines correct execution of business logic.

Affected Systems

The flaw affects RTI Connext Professional across multiple major releases. Vulnerable versions include those from 7.4.0 up to before 7.7.0.1; from 7.0.0 up to before 7.3.1.6; from 6.1.0 up to before 6.1.*; from 6.0.0 up to before 6.0.*; from 5.3.0 up to before 5.3.*; from 5.2.0 up to before 5.2.*; and from 4.1.x up to before 5.1.*.

Risk and Exploitability

With a base CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score is not provided, and the flaw is not listed in CISA’s KEV catalog, indicating no confirmed widespread exploitation yet. The likely attack vector is through application‑level interaction with Connext’s core libraries; it is inferred that an attacker could manipulate inputs or data passed to the affected components to trigger the incorrect calculation. As with many core‑library issues, the exploit would execute in the context of the vulnerable application, granting the attacker the same permissions as the running service.

Generated by OpenCVE AI on September 22, 2026 at 19:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RTI Connext Professional to version 7.7.0.1 or later to ensure the core library calculation is corrected.
  • If an upgrade is not immediately available, isolate the application by restricting network access to interfaces that invoke the vulnerable core libraries to reduce exposure.
  • Monitor application logs for abnormal or unexpected behavior that may indicate exploitation attempts, and configure alerts for such anomalies.

Generated by OpenCVE AI on September 22, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.1x before 5.1.*.
Title Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality.
First Time appeared Rti
Rti connext Professional
Weaknesses CWE-682
CPEs cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
Vendors & Products Rti
Rti connext Professional
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rti Connext Professional
cve-icon MITRE

Status: PUBLISHED

Assigner: RTI

Published:

Updated: 2026-09-22T18:48:01.536Z

Reserved: 2026-07-31T07:30:12.139Z

Link: CVE-2026-18459

cve-icon Vulnrichment

Updated: 2026-09-22T18:47:58.441Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:11.793

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-18459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T00:00:08Z

Weaknesses