Junglewise Threat Intelligence

CVE-2026-32863: NI LabVIEW out-of-bounds read in sentry_transaction_context_set_operation

CVE-2026-32863 · Severity: high · CVSS 7.8 · Published 2026-04-07

Technologies: NI Labview. Vendors: NI.

Executive brief

NI LabVIEW, a popular engineering software used for automated testing and data acquisition, is vulnerable to a memory corruption flaw. An attacker could exploit this by tricking a user into opening a specially crafted LabVIEW Virtual Instrument (.VI) file. If successful, this could allow the attacker to steal sensitive information or take full control of the user's computer.

Technical details

A memory corruption vulnerability exists in NI LabVIEW due to an out-of-bounds read within the 'sentry_transaction_context_set_operation()' function. The flaw is triggered when the application processes a specially crafted Virtual Instrument (.VI) file. This is a local attack vector requiring user interaction (opening the file). Successful exploitation can lead to arbitrary code execution or information disclosure by reading beyond allocated memory buffers. The vulnerability affects versions up to and including LabVIEW 2026 Q1 (26.1.0). NI has released patches for various versions, including LabVIEW 2026 Q1 Patch 1.

Affected products

  • NI LabVIEW 2026 Q1 (26.1.0) and prior versions

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory
  • 2026-04-07: patched

References

Related threats