Description
Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext Professional: from 7.5.0 before 7.7.0.1, from 7.3.0.10 before 7.3.1.6.
Published: 2026-09-22
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a format string injection that permits an attacker to control the format string used by the application’s core libraries. If exploited, the attacker can cause the application to interpret the string as a format specifier, potentially leading to arbitrary code execution or memory disclosure.

Affected Systems

RTI Connext Professional, Core Libraries. Affected versions include all releases from 7.5.0 up to, but not including, 7.7.0.1 and from 7.3.0.10 up to, but not including, 7.3.1.6.

Risk and Exploitability

The CVSS score of 9.2 indicates a critical severity. The EPSS score is not available, so the current exploitation probability is uncertain, though a lack of KEV listing means no known exploit has been reported yet. Based on the description, it is inferred that the attack could originate from any interface that accepts user‑controlled input to formatting functions, which may include networked API callers or local debug functions. The high severity combined with the absence of an existing exploit suggests that organizations should consider this a high priority for patching or mitigation.

Generated by OpenCVE AI on September 22, 2026 at 19:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to RTI Connext Professional 7.7.0.1 or newer for 7.5.0‑series users, or to 7.3.1.6 or newer for 7.3.0.10‑series users.
  • Ensure that any format strings used in application code are explicitly validated or that user input is never passed directly to formatting functions.
  • Conduct a security code review for additional format string vulnerabilities and apply general secure coding practices.

Generated by OpenCVE AI on September 22, 2026 at 19:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext Professional: from 7.5.0 before 7.7.0.1, from 7.3.0.10 before 7.3.1.6.
Title Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection.
First Time appeared Rti
Rti connext Professional
Weaknesses CWE-134
CPEs cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
Vendors & Products Rti
Rti connext Professional
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rti Connext Professional
cve-icon MITRE

Status: PUBLISHED

Assigner: RTI

Published:

Updated: 2026-09-22T18:46:56.035Z

Reserved: 2026-07-31T07:31:16.835Z

Link: CVE-2026-18461

cve-icon Vulnrichment

Updated: 2026-09-22T18:46:52.079Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:12.077

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-18461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:00:13Z

Weaknesses
  • CWE-134

    Use of Externally-Controlled Format String