Junglewise Threat Intelligence

CVE-2026-19781: Ashlar-Vellum Cobalt heap buffer overflow in VS file parsing

CVE-2026-19781 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

Ashlar-Vellum Cobalt is a design and visualization software used for engineering and technical drawings. A heap buffer overflow vulnerability in its VS file parser allows attackers to execute arbitrary code when a user opens a malicious file, potentially compromising the integrity of systems and enabling unauthorized access to sensitive design data or system credentials.

Technical details

A heap-based buffer overflow vulnerability exists in Ashlar-Vellum Cobalt's VS file parser due to insufficient validation of user-supplied data length before copying to a heap buffer. The attack vector is local (requires user interaction to open a malicious VS file), but remote delivery is possible via social engineering or malicious pages. An attacker can craft a specially formatted VS file that, when opened by a victim, triggers the overflow and achieves arbitrary code execution in the context of the Cobalt process. The vulnerability was patched in version 12.6.1204.210.

Affected products

  • Ashlar-Vellum Cobalt before 12.6.1204.210

Timeline

  • 2025-11-11: disclosed: Vulnerability reported to vendor
  • 2026-08-24: patched: Fixed in version 12.6.1204.210
  • 2026-08-24: advisory: Public advisory published (ZDI-26-587, CVE-2026-19781)

References