← Vulnerability feed

Vulnerability record · CVE-2026-49746 · published 7 August 2026

CVE-2026-49746: Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read ke…

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.

7.1 CVSS 3.1 High EPSS 0.15% · top 96.2% CWE-823 · CWE-823 Deferred
7.1CVSS 3.1 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
0Affected product versions listed by NVD
1References
3 Sep 2026Last modified by NVD

Description

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

References

Track CVE-2026-49746 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2026-49746), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.