ZDI-26-359: Samsung rlottie Numeric Truncation Remote Code Execution Vulnerability
Published Jun 11, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-8916.
Affected Software
1 affected component
Samsung rLottie
Event History
Jun 11, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-359?
The severity of ZDI-26-359 is rated 7.8 on the CVSS scale.
2
How do I fix ZDI-26-359?
To fix ZDI-26-359, update to the latest version of Samsung rlottie that addresses the vulnerability.
3
Who is affected by ZDI-26-359?
Users of Samsung rlottie are affected by the ZDI-26-359 vulnerability.
4
What type of vulnerability is ZDI-26-359?
ZDI-26-359 is a numeric truncation vulnerability that can lead to remote code execution.
5
What is required to exploit ZDI-26-359?
Exploitation of ZDI-26-359 requires interaction with the rlottie library.