CVE-2026-2394 Details
Description
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.3x before 5.1.*.
A buffer over-read vulnerability has been identified in RTI Connext Professional Core Libraries. This vulnerability allows for unauthorized reading of heap memory when the application parses XML types, potentially leading to information leakage or application crashes. The issue affects multiple versions of RTI Connext Professional, including versions 4.3x prior to 5.2.*, 5.3.0 prior to 5.3.*, 6.0.0 prior to 6.0.*, 6.1.0 prior to 6.1.*, 7.0.0 prior to 7.3.1.1, and 7.4.0 prior to 7.7.0.
Users can upgrade to RTI Connext Professional version 7.3.1.2 or 7.7.0, both of which include the necessary fix. For versions 6.1.2.29 or earlier, a patch is available upon request.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.rti.com/vulnerabilities/#cve-2026-2394 | RTI | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
| CWE-126 | Buffer Over-read | RTI |
Affected Products
| Product | Versions |
|---|---|
| rti connext professional | >= 4.3.0, <= 5.2.3 >= 5.3.0, <= 5.3.1.45 >= 6.0.0, <= 6.0.1.40 >= 6.1.0, <= 6.1.2.27 >= 7.0.0, < 7.3.1.1 >= 7.4.0, < 7.7.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Modified | RTI |
| Jun 17, 2026 | CVE Modified | RTI |
| Jun 17, 2026 | CVE Modified | RTI |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | RTI |