Description
Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 5.0.0 before 5.1.*.
Published: 2026-09-22
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Out‑of‑bounds read in RTI Connext Professional Core Libraries permits an attacker to consume portions of memory that lie beyond intended buffer limits. This flaw could expose sensitive internal data, such as authentication tokens or user information, depending on the context in which the vulnerable component is executed. The weakness is classified as CWE‑125, which generally allows an attacker to gain unintended visibility into memory contents, compromising confidentiality without immediate code execution.

Affected Systems

The vulnerability applies to versions of RTI Connext Professional that precede the following release points: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, and from 5.0.0 before 5.1.*. Systems running any of these binaries are at risk unless the software is upgraded beyond the cited versions.

Risk and Exploitability

The CVSS score of 6.8 places this issue in the medium severity range, indicating that while exploitation does not lead to immediate control, the potential for data leakage is significant. No EPSS data is available, so the likelihood of exploitation in the wild cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been identified as a high‑impact target by national security monitoring. Based on the description, it is inferred that the attack vector is local or requires some degree of code execution within the affected application; the mechanism for triggering the overread is not explicitly detailed.

Generated by OpenCVE AI on September 22, 2026 at 20:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RTI Connext Professional to version 7.7.0.1 or a later release that includes the patch for CVE‑2026‑18626.
  • If an upgrade cannot be performed immediately, restrict the privileges of the RTI Connext process and configure OS‑level memory protection (e.g., SELinux, AppArmor, or Windows Defender Exploit Protection) to limit access to sensitive memory pages.
  • Monitor system logs and network traffic for anomalous memory reads or unusual behavior, and apply network segmentation to isolate the RTI Connext services from critical infrastructure.

Generated by OpenCVE AI on September 22, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 5.0.0 before 5.1.*.
Title Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.
First Time appeared Rti
Rti connext Professional
Weaknesses CWE-125
CPEs cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
Vendors & Products Rti
Rti connext Professional
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rti Connext Professional
cve-icon MITRE

Status: PUBLISHED

Assigner: RTI

Published:

Updated: 2026-09-22T18:45:58.591Z

Reserved: 2026-08-03T08:20:41.882Z

Link: CVE-2026-18626

cve-icon Vulnrichment

Updated: 2026-09-22T18:45:55.776Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:12.363

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-18626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:15:09Z

Weaknesses