{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-18458", "assignerOrgId": "3f572a00-62e2-4423-959a-7ea25eff1638", "state": "PUBLISHED", "assignerShortName": "RTI", "dateReserved": "2026-07-31T07:29:34.430Z", "datePublished": "2026-09-22T17:50:17.977Z", "dateUpdated": "2026-09-22T18:48:29.246Z" }, "containers": { "cna": { "affected": [ { "defaultStatus": "unaffected", "modules": [ "Core Libraries" ], "product": "Connext Professional", "packageName": "connext_professional", "packageURL": "pkg:generic/connext_professional", "vendor": "RTI", "versions": [ { "lessThan": "7.7.0.1", "status": "affected", "version": "7.4.0", "versionType": "custom" }, { "lessThan": "7.3.1.6", "status": "affected", "version": "7.3.0", "versionType": "custom" }, { "lessThan": "6.1.*", "status": "affected", "version": "6.1.2.21", "versionType": "custom" } ] } ], "datePublic": "2026-09-15T17:47:50.129Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.
This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6, from 6.1.2.21 before 6.1.*.
" } ], "value": "Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6, from 6.1.2.21 before 6.1.*." } ], "impacts": [ { "capecId": "CAPEC-540", "descriptions": [ { "lang": "en", "value": "CAPEC-540 Overread Buffers" } ] } ], "metrics": [ { "cvssV4_0": { "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "Safety": "NOT_DEFINED", "attackComplexity": "LOW", "attackRequirements": "NONE", "attackVector": "LOCAL", "baseScore": 6.8, "baseSeverity": "MEDIUM", "privilegesRequired": "LOW", "providerUrgency": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "userInteraction": "NONE", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", "version": "4.0", "vulnAvailabilityImpact": "HIGH", "vulnConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "vulnerabilityResponseEffort": "NOT_DEFINED" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] }, { "cvssV4_0": { "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "Safety": "NOT_DEFINED", "attackComplexity": "LOW", "attackRequirements": "NONE", "attackVector": "LOCAL", "baseScore": 6.8, "baseSeverity": "MEDIUM", "privilegesRequired": "LOW", "providerUrgency": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "userInteraction": "NONE", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", "version": "4.0", "vulnAvailabilityImpact": "HIGH", "vulnConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "vulnerabilityResponseEffort": "NOT_DEFINED" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "Security Extensions Enabled" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] }, { "descriptions": [ { "cweId": "CWE-685", "description": "CWE-685 Function Call With Incorrect Number of Arguments", "lang": "en", "type": "CWE" } ] }, { "descriptions": [ { "cweId": "CWE-843", "description": "CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "orgId": "3f572a00-62e2-4423-959a-7ea25eff1638", "shortName": "RTI", "dateUpdated": "2026-09-22T17:50:17.977Z" }, "references": [ { "url": "https://www.rti.com/vulnerabilities/#cve-2026-18458" } ], "source": { "discovery": "UNKNOWN" }, "title": "Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.", "x_generator": { "engine": "RTI Lubna 1.18.7" }, "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negated": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*", "versionStartIncluding": "7.4.0", "versionEndExcluding": "7.7.0.1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*", "versionStartIncluding": "7.3.0", "versionEndExcluding": "7.3.1.6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.1.2.21", "versionEndExcluding": "6.1.*" } ] } ] } ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-09-22T18:48:21.717194Z", "id": "CVE-2026-18458", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-22T18:48:29.246Z" } } ] } }