Impact
A memory corruption vulnerability in NI LabVIEW can allow an attacker to read beyond array bounds when loading a specially crafted VI, potentially leading to information disclosure or arbitrary code execution. The weakness is a classic out-of-bounds read (CWE-125) that can compromise the confidentiality, integrity or availability of a system. During exploitation the attacker must convince a local user to open a malicious VI, at which point the corrupt read can be leveraged to compromise the local process. The severity is reflected in a CVSS score of 8.5, indicating high potential impact.
Affected Systems
NI LabVIEW versions 2026 Q3 (26.3.0) and all earlier releases are affected. The vulnerability applies to the standard NI LabVIEW product.
Risk and Exploitability
The CVSS score of 8.5 classifies the flaw as high severity, and although EPSS data is not available, the lack of a KEV listing does not diminish the risk of exploitation. Due to the local user interaction requirement, the attack vector is inferred as a social engineering or phishing scenario where a user must intentionally open a malicious VI file. Once executed, the exploit could allow full code execution under the context of the current user. The vulnerability is therefore considered high risk for environments where LabVIEW is used by multiple users or where untrusted VI files may be opened.
OpenCVE Enrichment