Low severity3.3NVD Advisory· Published Jul 6, 2026· Updated Jul 7, 2026
CVE-2026-14786
CVE-2026-14786
Description
A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the file libr/util/str.c. The manipulation results in integer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 11ac224c0eb8d57830fccc99e1c1cd8e5d958813. It is best practice to apply a patch to resolve this issue.
Affected products
3- Range: <=6.1.6
Patches
Vulnerability mechanics
References
6- github.com/radareorg/radare2/commit/11ac224c0eb8d57830fccc99e1c1cd8e5d958813nvdPatch
- github.com/radareorg/radare2/issues/26047nvdExploitIssue Tracking
- vuldb.com/cve/CVE-2026-14786nvdThird Party AdvisoryVDB Entry
- vuldb.com/submit/850386nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/376375nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/376375/ctinvdPermissions RequiredVDB Entry
News mentions
1- Radare2: Nine Local Vulnerabilities Disclosed Together, Exploits Publicly AvailableVypr Intelligence · Jul 7, 2026