CVE-2026-32863 is a memory corruption vulnerability involving an out-of-bounds read in the sentry_transaction_context_set_operation() function within NI LabVIEW versions 26.1.0 and earlier. The flaw could enable information disclosure or arbitrary code execution if an attacker successfully tricks a user into opening a malicious VI file. The vulnerability presents a HIGH severity risk with a CVSS score of 7.8, featuring a local attack vector with low complexity and no privilege requirements. The attack depends on user interaction, but once successful, it could compromise confidentiality, integrity, and availability of the affected system. There is no current evidence of active exploitation, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on the Hot List. The extremely low EPSS score of 0.00016 further indicates minimal real-world exploitation activity, suggesting this remains a theoretical threat requiring user intervention for successful compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2022CPE matchmatch criteria | cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:* | ||
2023CPE matchmatch criteria | cpe:2.3:a:ni:labview:2023:q1:*:*:*:*:*:* | ||
2023CPE matchmatch criteria | cpe:2.3:a:ni:labview:2023:q3:*:*:*:*:*:* | ||
2023CPE matchmatch criteria | cpe:2.3:a:ni:labview:2023:q3_patch1:*:*:*:*:*:* | ||
2023CPE matchmatch criteria | cpe:2.3:a:ni:labview:2023:q3_patch2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.