SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82591

MEDIUM · CVSS 5.3 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-30 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the Open Asset Import Library (Assimp) versions up to 6.0.2, specifically within the MD5Importer::MakeDataUnique function, where improper handling of the iNewIndex argument can lead to a heap-based buffer overflow. This flaw allows for potential local exploitation, which could compromise the integrity of the application. Developers and organizations utilizing Assimp in their projects should prioritize applying the provided patch to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82591
Severity
MEDIUM
CVSS
5.3
EPSS
0.12%

Original NVD Description

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewIndex leads to heap-based buffer overflow. The attack can only be performed from a local environment. The identifier of the patch is bf9dabb617c46e5133dac65cca6bff177917afcb. Applying a patch is the recommended action to fix this issue.