Description
Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. This issue affects Connext Professional: from 7.6.0 before 7.7.0.1.
Published: 2026-09-22
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: File Manipulation
Action: Patch
AI Analysis

Impact

This vulnerability is a classic use-after-free flaw found in the Security Plugins of RTI Connext Professional. The flaw permits an attacker who can trigger the freed memory to manipulate file contents, potentially overwriting or corrupting configuration or log files. The impact is data integrity violation and could lead to unauthorized changes or denial of service if critical files are corrupted.

Affected Systems

Affected versions are all releases from 7.6.0 up to but excluding 7.7.0.1 of RTI Connext Professional. Users running any of these builds must verify the installed version and plan an update. No other products or versions are affected according to the CNA data.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity, and the lack of an EPSS score means no recent exploitation data is available, though the vulnerability remains in the CWE-416 category. The vulnerability is not catalogued in CISA's KEV list. Based on the description, the likely attack vector is any component that interacts with the Security Plugins that could be supplied malicious data; thus an attacker may need code execution or local access to create the conditions for the use-after-free. In absence of exploitation evidence, administrators should treat it as a high-risk local vulnerability.

Generated by OpenCVE AI on September 22, 2026 at 19:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RTI Connext Professional to version 7.7.0.1 or later to eliminate the flaw.
  • If an upgrade is not immediately feasible, disable or restrict the Security Plugins module and ensure the memory used by it is not exposed to untrusted input.
  • Apply strict file system permissions to the directories used by the application to prevent unauthorized writes, limiting the impact if the flaw is exploited.

Generated by OpenCVE AI on September 22, 2026 at 19:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. This issue affects Connext Professional: from 7.6.0 before 7.7.0.1.
Title Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.
First Time appeared Rti
Rti connext Professional
Weaknesses CWE-416
CPEs cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
Vendors & Products Rti
Rti connext Professional
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rti Connext Professional
cve-icon MITRE

Status: PUBLISHED

Assigner: RTI

Published:

Updated: 2026-09-22T18:54:55.279Z

Reserved: 2026-05-18T15:46:09.935Z

Link: CVE-2026-8849

cve-icon Vulnrichment

Updated: 2026-09-22T18:54:47.477Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:29.690

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-8849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:00:13Z

Weaknesses