Executive brief
NI LabVIEW is a system for designing and building industrial automation and test systems. CVE-2026-64203 is a memory corruption vulnerability in LabVIEW's QualifiedName prepend function that can enable information disclosure or arbitrary code execution when a user opens a malicious VI file. An attacker can craft a specially crafted VI to trigger out-of-bounds memory access, potentially compromising system security and data integrity.
Technical details
CVE-2026-64203 is an out-of-bounds read vulnerability in the QualifiedName prepend function within NI LabVIEW. The vulnerability is triggered when a user opens a specially crafted VI file, requiring user interaction but no authentication or elevated privileges. An attacker can exploit this memory corruption to read sensitive information from process memory or execute arbitrary code with the privileges of the user running LabVIEW. The vulnerability affects LabVIEW 2026 Q3 (26.3.0) and all prior versions; patches are available through NI Update Service or NI Package Manager, with specific patch versions recommended for each release line (2026 Q3 Patch 1, 2025 Q3 Patch 5, 2024 Q3 Patch 7, 2023 Q3 Patch 10).
Affected products
- NI LabVIEW 2026 Q3 (26.3.0) and prior
Timeline
- 2026-08-25: disclosed