CVE-2026-14786: A security flaw has been discovered in radareorg radar
CVE-2026-14786 analysis covering impact, affected products, versions, remediation, and cross-checked defender guidance.
CVE-2026-14786 is a vulnerability published by NVD on 7/6/2026.
What happened
A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the file libr/util/str.c. The manipulation results in integer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 11ac224c0eb8d57830fccc99e1c1cd8e5d958813. It is best practice to apply a patch to resolve this issue.
Affected products and versions
- radare radare2 unspecified version (before 6.1.8)
Severity and weakness
CVSS: LOW 3.3. Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L.
Weaknesses: CWE-189, CWE-190.
Known exploitation
No CISA KEV entry is currently attached to the NVD record.
What defenders should do
- Identify whether the affected product and version range exists in production.
- Review vendor advisories and release notes before change windows.
- Patch, upgrade, disable the vulnerable component, or apply vendor mitigations.
- Verify the running version after deployment, not only the package inventory.