Impact
An out-of-bounds read vulnerability in NI LabVIEW allows an attacker to read memory beyond the intended buffer, which can lead to information disclosure or arbitrary code execution when a user opens a specially crafted VI file. This weakness, identified as CWE-125, compromises confidentiality and integrity of the system.
Affected Systems
NI LabVIEW version 2026 Q3 (26.3.0) and earlier releases.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and the exploit requires a user to open a malicious VI, suggesting a social-engineering vector. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog, but the combination of a high CVSS score and user-action prerequisite still poses a significant risk to exposed installations.
OpenCVE Enrichment