Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
1.9
CVE-2026-14760: radare2: Local Attack Possible Through Code Execution
CVE-2026-14760
Summary
A vulnerability in radare2 version 6.1.6 and earlier allows an attacker with local access to potentially execute malicious code. This could lead to unauthorized actions on a system. We recommend updating to the latest version to address this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| radare | radare2 |
< 6.1.8 cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* |
Original title
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manip...
Original description
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a patch to correct this issue.
nvd CVSS2.0
1.7
nvd CVSS3.1
3.3
nvd CVSS4.0
1.9
Vulnerability type
CWE-119
Buffer Overflow
CWE-416
Use After Free
- https://github.com/radareorg/radare2/
- https://github.com/radareorg/radare2/commit/8b25c773785d85cb0103410a0905089d2869...
- https://github.com/radareorg/radare2/issues/26044
- https://vuldb.com/cve/CVE-2026-14760
- https://vuldb.com/submit/850384
- https://vuldb.com/vuln/376349
- https://vuldb.com/vuln/376349/cti
Published: 5 Jul 2026 · Updated: 8 Jul 2026 · First seen: 5 Jul 2026