Description
Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 5.0.0 before 5.1.*.
Published: 2026-06-17
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential Information Disclosure via out-of-bounds read
Action: Immediate Patch
AI Analysis

Impact

The flaw is an out‑of‑bounds read in the core libraries of RTI Connext Professional; it permits reading data past buffer boundaries. This can expose contents residing in memory, such as secrets or other confidential data, and is classified as CWE‑125. No elevation of privilege or code execution is required, but sensitive information may be disclosed.

Affected Systems

The vulnerability affects RTI Connext Professional deployments across several major releases: from version 7.4.0 up to but not including 7.7.0; from 7.0.0 up to but not including 7.3.1.3; from 6.1.0 up to but not including 6.1.*; from 6.0.0 up to but not including 6.0.*; from 5.3.0 up to but not including 5.3.*; from 5.2.0 up to but not including 5.2.*; from 5.0.0 up to but not including 5.1.*.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, while the EPSS score of less than 1% signals a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires access to the same process memory or a privilege level that allows memory probing. The resulting information disclosure makes it a significant risk for environments that handle sensitive data within Connext services.

Generated by OpenCVE AI on September 22, 2026 at 20:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest un‑affected release such as 7.7.0 or newer, or the corresponding newer minor release in the 7.3.x, 6.1.x, 6.0.x, 5.3.x, or 5.2.x series.
  • Limit access to the Connext services by restricting network connections and operating‑system accounts to trusted administrators only, minimizing the potential attack surface.
  • Increase monitoring of application logs for unexpected memory access failures or crashes, and investigate any anomalies that could signal an attempted exploitation of the out‑of‑bounds read.

Generated by OpenCVE AI on September 22, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*. Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 5.0.0 before 5.1.*.

Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*.
Title Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.
First Time appeared Rti
Rti connext Professional
Weaknesses CWE-125
CPEs cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
Vendors & Products Rti
Rti connext Professional
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:L/SA:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Rti Connext Professional
cve-icon MITRE

Status: PUBLISHED

Assigner: RTI

Published:

Updated: 2026-09-22T17:50:09.013Z

Reserved: 2026-03-10T17:09:23.192Z

Link: CVE-2026-3894

cve-icon Vulnrichment

Updated: 2026-06-17T18:01:10.707Z

cve-icon NVD

Status : Modified

Published: 2026-06-17T18:17:44.287

Modified: 2026-09-22T18:17:14.190

Link: CVE-2026-3894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:00:16Z

Weaknesses