Stack-based buffer overflow in Simcenter Femap and Simcenter Nastran - CVE-2026-59086

 

Stack-based buffer overflow in Simcenter Femap and Simcenter Nastran - CVE-2026-59086

Published: August 14, 2026


Vulnerability identifier: #VU142486
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59086
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error while parsing specially strings as argument for one of the application binaries. A local attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Simcenter Femap
Simcenter Nastran

How to mitigate CVE-2026-59086

Install updates from vendor's website.

Simcenter Femap - update to 2606
Simcenter Nastran - update to 2606

External References

Related Security Bulletins