CVE-2026-14786
LOWDescription
A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the file libr/util/str.c. The manipulation results in integer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 11ac224c0eb8d57830fccc99e1c1cd8e5d958813. It is best practice to apply a patch to resolve this issue.
Is your site exposed to CVE-2026-14786?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| radare | radare2 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2026-14786? +
How severe is CVE-2026-14786? +
What products are affected by CVE-2026-14786? +
How do I check if I'm vulnerable to CVE-2026-14786? +
Related Vulnerabilities
A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the …
A vulnerability classified as critical has been found in libzvbi up to 0.2.43. This affects the function vbi_capture_sim_load_caption of the …
A vulnerability classified as critical was found in libzvbi up to 0.2.43. This vulnerability affects the function vbi_search_new of the …
A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the …
A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue …
A vulnerability was found in libzvbi up to 0.2.43. It has been declared as problematic. Affected by this vulnerability is …