There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ni:labview:2023:q1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch2:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch3:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch4:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch5:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch6:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch7:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch8:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch9:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:-:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q1_patch1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q3:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q3_patch1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q3_patch2:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q3_patch3:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q3_patch4:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q3_patch5:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q3_patch6:*:*:*:*:*:* cpe:2.3:a:ni:labview:2025:q1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2025:q1_patch1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2025:q1_patch2:*:*:*:*:*:* cpe:2.3:a:ni:labview:2025:q1_patch3:*:*:*:*:*:* cpe:2.3:a:ni:labview:2025:q3:*:*:*:*:*:* cpe:2.3:a:ni:labview:2025:q3_patch1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2025:q3_patch2:*:*:*:*:*:* cpe:2.3:a:ni:labview:2025:q3_patch3:*:*:*:*:*:* cpe:2.3:a:ni:labview:2025:q3_patch4:*:*:*:*:*:* cpe:2.3:a:ni:labview:2026:q1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2026:q1_patch1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2026:q1_patch2:*:*:*:*:*:* cpe:2.3:a:ni:labview:2026:q3:*:*:*:*:*:* |
Tue, 25 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q3 and prior versions. | |
| Title | Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI LabVIEW | |
| First Time appeared |
Ni
Ni labview |
|
| Weaknesses | CWE-195 | |
| CPEs | cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ni
Ni labview |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: NI
Published: 2026-08-25T16:09:03.396Z
Updated: 2026-08-31T15:15:06.186Z
Reserved: 2026-07-30T22:06:03.338Z
Link: CVE-2026-18444
Updated: 2026-08-25T19:42:47.043Z
Status : Analyzed
Published: 2026-08-25T17:17:05.803
Modified: 2026-09-08T14:30:51.530
Link: CVE-2026-18444
No data.