SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-19999

MEDIUM · CVSS 6.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

A buffer overflow vulnerability exists in the Assimp library's 3DGS MDL7 Bone Transformation Key Parser, specifically in the handling of the transmatrix_count/pcBoneTransforms argument. This flaw can be exploited remotely, potentially allowing attackers to execute arbitrary code. Organizations using affected versions of the Open Asset Import Library should prioritize applying the patch to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19999
Severity
MEDIUM
CVSS
6.3
EPSS
0.27%

Original NVD Description

A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Bone Transformation Key Parser. The manipulation of the argument transmatrix_count/pcBoneTransforms leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The identifier of the patch is 50d767984e78d51b53e2020fdf0967fd624bc377. It is recommended to apply a patch to fix this issue.