Impact
The vulnerability is a memory corruption flaw caused by an out-of-bounds write in NI LabVIEW when a user loads a VI. According to the description, this flaw can lead to information disclosure or arbitrary code execution, which is consistent with the CWE-787 classification.
Affected Systems
NI LabVIEW 2026 Q3 (build 26.3.0) and all earlier releases are affected. The flaw is present in all known NI LabVIEW products that include the VI loader.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity level. There is no EPSS score available, so the precise exploitation likelihood is unknown, but the vulnerability is not listed in the CISA KEV catalog at this time. Exploitation requires a user to open a specially crafted VI, so the attack vector is local user interaction, possibly via phishing or social engineering.
OpenCVE Enrichment