Junglewise Threat Intelligence

CVE-2026-30799: RTI Connext Professional identity spoofing in Security Plugins

CVE-2026-30799 · Severity: info · CVSS 6.1 · Published 2026-06-17

Vendors: Rti.

Executive brief

A vulnerability in the security plugins of RTI Connext Professional, a widely used middleware for industrial and mission-critical systems, allows an attacker to spoof identities. By bypassing authentication for critical functions, an unauthorized user could impersonate legitimate system components, potentially leading to unauthorized data modification or service disruption. This could impact the integrity and reliability of communications in environments like aerospace, defense, or critical infrastructure.

Technical details

A Missing Authentication for Critical Function vulnerability (CWE-306) exists in the Security Plugins of RTI Connext Professional. The flaw allows an attacker with low privileges to bypass authentication mechanisms and spoof identities within the DDS (Data Distribution Service) network. According to the CVSS 4.0 vector, the attack requires a specific 'threat' or environmental condition (AT:P) but can be executed over the network without user interaction. Successful exploitation can lead to high impacts on system integrity and availability. Affected versions include various releases across the 5.3.x, 6.x, 7.0.x, and 7.4.x branches; users are advised to upgrade to versions 7.7.0 or other patched releases as specified by the vendor.

Affected products

  • RTI Connext Professional (Security Plugins) 7.4.0 before 7.7.0, 7.0.0 before 7.3.*, 6.1.0 before 6.1.*, 6.0.0 before 6.0.*, 5.3.0 before 5.3.*

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References