8.5

CVE-2026-32861

Out-of-Bounds Write Vulnerability in NI LabVIEW when loading lvclass file

There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .lvclass file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ni ≫ Labview Version <= 2022
Ni ≫ Labview Version 2023 Update q1
Ni ≫ Labview Version 2023 Update q3
Ni ≫ Labview Version 2023 Update q3_patch1
Ni ≫ Labview Version 2023 Update q3_patch2
Ni ≫ Labview Version 2023 Update q3_patch3
Ni ≫ Labview Version 2023 Update q3_patch4
Ni ≫ Labview Version 2023 Update q3_patch5
Ni ≫ Labview Version 2023 Update q3_patch6
Ni ≫ Labview Version 2023 Update q3_patch7
Ni ≫ Labview Version 2023 Update q3_patch8
Ni ≫ Labview Version 2024 Update -
Ni ≫ Labview Version 2024 Update q1
Ni ≫ Labview Version 2024 Update q1_patch1
Ni ≫ Labview Version 2024 Update q3
Ni ≫ Labview Version 2024 Update q3_patch1
Ni ≫ Labview Version 2024 Update q3_patch2
Ni ≫ Labview Version 2024 Update q3_patch3
Ni ≫ Labview Version 2024 Update q3_patch4
Ni ≫ Labview Version 2024 Update q3_patch5
Ni ≫ Labview Version 2025 Update q1
Ni ≫ Labview Version 2025 Update q1_patch1
Ni ≫ Labview Version 2025 Update q1_patch2
Ni ≫ Labview Version 2025 Update q1_patch3
Ni ≫ Labview Version 2025 Update q3
Ni ≫ Labview Version 2025 Update q3_patch1
Ni ≫ Labview Version 2025 Update q3_patch2
Ni ≫ Labview Version 2025 Update q3_patch3
Ni ≫ Labview Version 2026 Update q1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.123
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@ni.com 8.5 0 0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
security@ni.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/lv-class-file-parsing-memory-corruption-vulnerability-in-ni-labview.html
Vendor Advisory