CVE-2026-18444: Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI LabVIEW
There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Users of NI LabVIEW 2026 Q3 and prior versions are affected, particularly when they open VI files obtained from untrusted or unverified sources.
What must an attacker do to exploit this issue?
An attacker must persuade a user to open a specially crafted VI file. The supplied severity vector indicates local attack vector and user interaction are required, while no privileges are required.
What is the potential impact of successful exploitation?
Successful exploitation may cause information disclosure or arbitrary code execution. The severity vector also indicates potential impact to confidentiality, integrity, and availability.