Impact
NI LabVIEW is vulnerable to an out‑of‑bounds read that can corrupt memory when a victim opens a specially crafted VI. The flaw can expose sensitive information or allow an attacker to execute arbitrary code on the compromised machine, as the exploited memory corruption is not confined to read‑only data.
Affected Systems
The vulnerability applies to NI LabVIEW versions 2026 Q3 (26.3.0) and all earlier releases. Users running any of these versions are at risk unless the software is upgraded to a fixed release.
Risk and Exploitability
The CVSS score of 8.5 indicates a high‑severity risk, but the EPSS score is not available and the issue is not listed in the CISA KEV catalog. Exploitation requires a user to open a malicious VI file, so the attack vector is most likely local or through social engineering. Although a network‑based attack is not implied, any mechanism that delivers the crafted VI to a target can lead to successful exploitation.
OpenCVE Enrichment