Junglewise Threat Intelligence

CVE-2026-32861: NI LabVIEW out-of-bounds write in LVCLASS file parsing

CVE-2026-32861 · Severity: high · CVSS 7.8 · Published 2026-04-07

Technologies: NI Labview. Vendors: NI.

Executive brief

NI LabVIEW, a popular system-design platform and development environment for engineers, is vulnerable to a memory corruption issue when processing specific project files. An attacker could trick a user into opening a malicious .lvclass file, potentially leading to unauthorized data access or the ability to run harmful code on the user's computer. This could compromise sensitive engineering data or disrupt critical operations.

Technical details

A memory corruption vulnerability (CWE-787: Out-of-bounds Write) exists in NI LabVIEW's file parsing logic for LV Class (.lvclass) files. The flaw is triggered when the application attempts to load a specially crafted, corrupted file, leading to an out-of-bounds write. While the attack vector is local, it requires user interaction to open the malicious file. Successful exploitation can result in arbitrary code execution or information disclosure within the context of the LabVIEW process. NI has released patches for LabVIEW versions 2023 through 2026 to address this issue.

Affected products

  • NI LabVIEW 2026 Q1 (26.1.0) and prior versions

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory: Vendor advisory published by NI
  • 2026-04-07: patched: Patches released for LabVIEW 2023, 2024, 2025, and 2026 versions

References

Related threats