Description
Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*.
Published: 2026-09-22
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Improper Access Control / Resource Manipulation
Action: Patch Update
AI Analysis

Impact

Integer overflow or wraparound in RTI Connext Professional core libraries permits an attacker to manipulate shared resources. The flaw arises when an attacker can supply control data that causes the library to incorrectly calculate addresses or indices, leading to unauthorized modifications or reads of data structures. This can result in privilege escalation within a shared process or denial of service if critical shared objects are corrupted. The weakness is identified as CWE‑190 and CWE‑284.

Affected Systems

RTI Connext Professional is impacted. Vulnerable releases include any from version 7.4.0 up to but not including 7.7.0.1, from 7.0.0 up to but not including 7.3.1.6, and all 6.1.0 releases prior to the last 6.1.*. Systems using these versions should verify their exact build and consider remediation.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.3, indicating high severity. EPSS is not reported, so recent exploitation probability cannot be quantified; however, the flaw involves an integer overflow that can be triggered in a shared context, implying that a remote or local attacker with access to the system could exploit it. The CVE is not listed in CISA KEV, but the high impact warrants precautionary measures.

Generated by OpenCVE AI on September 22, 2026 at 19:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest RTI Connext Professional release that excludes the vulnerable ranges.
  • Apply any vendor‑supplied patch or hotfix addressing integer overflow and access control issues as soon as it becomes available.
  • Restrict network exposure of RTI Connext services by implementing firewall rules or network segmentation to limit connections to trusted hosts only.

Generated by OpenCVE AI on September 22, 2026 at 19:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*.
Title Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation.
First Time appeared Rti
Rti connext Professional
Weaknesses CWE-190
CWE-284
CPEs cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
Vendors & Products Rti
Rti connext Professional
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rti Connext Professional
cve-icon MITRE

Status: PUBLISHED

Assigner: RTI

Published:

Updated: 2026-09-22T18:46:32.313Z

Reserved: 2026-07-31T07:31:45.736Z

Link: CVE-2026-18462

cve-icon Vulnrichment

Updated: 2026-09-22T18:46:28.827Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:12.220

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-18462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:00:13Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-284

    Improper Access Control