Junglewise Threat Intelligence

CVE-2026-2674: RTI Connext Professional out-of-bounds write in Core Libraries

CVE-2026-2674 · Severity: info · CVSS 4.8 · Published 2026-06-17

Technologies: Rti Connext Professional. Vendors: Rti.

Executive brief

RTI Connext Professional, a software framework used for real-time data distribution in industrial and mission-critical systems, contains a flaw in how it handles data buffers. A local attacker with basic user access could exploit this to cause a system crash or potentially modify data, impacting the reliability and integrity of the communication services. This affects the Queueing, Core Libraries, and Persistence services within the suite.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in RTI Connext Professional within the Queueing Service, Core Libraries, and Persistence Service. The flaw allows for buffer overflows when processing specific data. According to the CVSS:4.0 vector, the attack vector is local (AV:L) and requires low privileges (PR:L) with no user interaction. Successful exploitation can lead to a partial loss of integrity and availability (VI:L/VA:L) by allowing an attacker to write data past the end of an intended buffer. Affected versions include the 7.4.x, 7.0.x, and 6.1.x branches; users should update to versions 7.7.0, 7.3.1.3, or the latest 6.1.x patch respectively.

Affected products

  • RTI Connext Professional 7.4.0 before 7.7.0, 7.0.0 before 7.3.1.3, 6.1.0 before 6.1.*

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References